7.5
    High

    CVE-2005-3509

    Last Modified: 22 Dec 2016

    Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.

    Source:Mousehack
    Published:6 Nov 2005
    7.5
    High

    CVE-2005-3508

    Last Modified: 26 Jun 2013

    SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.

    Published:6 Nov 2005
    5
    Medium

    CVE-2005-3507

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.

    Published:6 Nov 2005
    7.2
    High

    CVE-2005-3503

    Last Modified: 19 May 2017

    chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

    Source:Hunger
    Published:5 Nov 2005
    5
    Medium

    CVE-2005-3493

    Last Modified: 16 Apr 2026

    Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port.

    Source:Luigi Auriemma
    Published:4 Nov 2005
    5
    Medium

    CVE-2005-3492

    Last Modified: 16 Apr 2026

    FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference.

    Source:Luigi Auriemma
    Published:4 Nov 2005
    7.5
    High

    CVE-2005-3491

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1) version, (2) name, and (3) model fields.

    Source:Luigi Auriemma
    Published:4 Nov 2005
    7.5
    High

    CVE-2005-3489

    Last Modified: 15 Nov 2017

    Buffer overflow in Asus Video Security 3.5.0.0 and earlier, when using authorization, allows remote attackers to execute arbitrary code via a long username/password string.

    Source:Luigi Auriemma
    Published:4 Nov 2005
    7.8
    High

    CVE-2005-3488

    Last Modified: 16 Apr 2026

    Scorched 3D 39.1 (bf) and earlier allows remote attackers to cause a denial of service (long loop and server hang) via a negative numplayers value that bypasses a signed check in ServerConnectHandler.cpp.

    Source:Luigi Auriemma
    Published:3 Nov 2005
    7.5
    High

    CVE-2005-3487

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, (4) a long command that is not properly handled in ComsMessageHandler.cpp when generating an error message, (5) a long UniqueID value in Logger.cpp, and possibly other unspecified vectors.

    Source:Luigi Auriemma
    Published:3 Nov 2005
    7.5
    High

    CVE-2005-3486

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

    Source:Luigi Auriemma
    Published:3 Nov 2005
    7.5
    High

    CVE-2005-3485

    Last Modified: 16 Apr 2026

    Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player name.

    Source:Luigi Auriemma
    Published:3 Nov 2005
    7.5
    High

    CVE-2005-3483

    Last Modified: 16 Apr 2026

    Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than the specified data block size.

    Source:Luigi Auriemma
    Published:3 Nov 2005
    7.5
    High

    CVE-2005-3478

    Last Modified: 25 Jun 2013

    SQL injection vulnerability in index.php in PHPCafe.net Tutorials Manager 1.0 Beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:almaster
    Published:3 Nov 2005
    5
    Medium

    CVE-2005-3475

    Last Modified: 16 Apr 2026

    Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests.

    Source:Expanders
    Published:3 Nov 2005
    4.3
    Medium

    CVE-2005-3473

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.

    Published:3 Nov 2005
    7.5
    High

    CVE-2005-3469

    Last Modified: 26 Jun 2013

    SQL injection vulnerability in index.php in News2Net 3.0.0.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:Mousehack
    Published:2 Nov 2005
    5
    Medium

    CVE-2005-3432

    Last Modified: 25 Jun 2013

    MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.

    Source:Preben Nylokken
    Published:2 Nov 2005
    7.5
    High

    CVE-2005-3423

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbulletin3.php.

    Source:RusH
    Published:1 Nov 2005
    4.3
    Medium

    CVE-2005-3422

    Last Modified: 25 Jun 2013

    Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Source:syst3m_f4ult
    Published:1 Nov 2005
    4.3
    Medium

    CVE-2005-3412

    Last Modified: 26 Jun 2013

    Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag.

    Source:gladiator
    Published:1 Nov 2005
    4.3
    Medium

    CVE-2005-3411

    Last Modified: 25 Jun 2013

    Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.

    Source:h4xorcrew
    Published:1 Nov 2005
    7.5
    High

    CVE-2005-3408

    Last Modified: 25 Jun 2013

    SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands via the limit parameter.

    Source:svsecurity
    Published:1 Nov 2005
    7.5
    High

    CVE-2005-3405

    Last Modified: 24 Oct 2016

    ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.

    Source:Andreas Sandblad
    Published:1 Nov 2005
    7.5
    High

    CVE-2005-3404

    Last Modified: 24 Oct 2016

    Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php.

    Source:Andreas Sandblad
    Published:1 Nov 2005
    4.3
    Medium

    CVE-2005-3397

    Last Modified: 26 Jun 2013

    Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.

    Source:_6mO_HaCk
    Published:1 Nov 2005
    7.5
    High

    CVE-2005-3395

    Last Modified: 25 Jun 2013

    SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.

    Source:almaster
    Published:1 Nov 2005
    7.5
    High

    CVE-2005-3394

    Last Modified: 25 Jun 2013

    Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.

    Published:1 Nov 2005
    7.5
    High

    CVE-2005-3390

    Last Modified: 26 Jun 2013

    The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS" fileupload field.

    Source:rgod
    Published:31 Oct 2005
    4.3
    Medium

    CVE-2005-3388

    Last Modified: 25 Jun 2013

    Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

    Source:Stefan Esser
    Published:31 Oct 2005
    7.5
    High

    CVE-2005-3369

    Last Modified: 25 Jun 2013

    Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.

    Published:29 Oct 2005
    4.3
    Medium

    CVE-2005-3368

    Last Modified: 25 Jun 2013

    Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:bhfh01
    Published:29 Oct 2005
    7.5
    High

    CVE-2005-3363

    Last Modified: 23 Jun 2013

    SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

    Source:almaster
    Published:29 Oct 2005
    4.9
    Medium

    CVE-2005-3358

    Last Modified: 6 Sept 2016

    Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.

    Source:Doug Chapman
    Published:13 Dec 2005
    7.2
    High

    CVE-2005-3346

    Last Modified: 9 Nov 2017

    Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.

    Source:Charles Stevenson
    Published:20 Nov 2005
    4.3
    Medium

    CVE-2005-3334

    Last Modified: 23 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.

    Source:Lostmon
    Published:27 Oct 2005
    7.5
    High

    CVE-2005-3332

    Last Modified: 23 Jun 2013

    PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter.

    Source:X
    Published:27 Oct 2005
    7.5
    High

    CVE-2005-3330

    Last Modified: 25 Jun 2013

    The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

    Source:D. Fabian
    Published:27 Oct 2005
    4.3
    Medium

    CVE-2005-3329

    Last Modified: 23 Jun 2013

    Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.

    Source:Bernhard Mueller
    Published:27 Oct 2005
    7.5
    High

    CVE-2005-3326

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.

    Source:Animal
    Published:27 Oct 2005
    7.5
    High

    CVE-2005-3325

    Last Modified: 23 Jun 2013

    Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.

    Source:Remco Verhoef
    Published:27 Oct 2005
    7.5
    High

    CVE-2005-3324

    Last Modified: 23 Jun 2013

    SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:rgod
    Published:27 Oct 2005
    2.6
    Low

    CVE-2005-3320

    Last Modified: 23 Jun 2013

    Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web script or HTML via the err parameter in the panel script.

    Source:farhad koosha
    Published:27 Oct 2005
    7.5
    High

    CVE-2005-3315

    Last Modified: 25 Jun 2013

    Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter parameters to reports/default.asp.

    Source:Dennis Rand
    Published:30 Oct 2005
    7.5
    High

    CVE-2005-3314

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments."

    Source:Metasploit
    Published:18 Nov 2005
    4.3
    Medium

    CVE-2005-3308

    Last Modified: 30 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.

    Source:sikikmail
    Published:25 Oct 2005
    5
    Medium

    CVE-2005-3307

    Last Modified: 23 Jun 2013

    Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.

    Published:25 Oct 2005
    7.5
    High

    CVE-2005-3305

    Last Modified: 16 Nov 2016

    Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections file, and (5) the dl_id parameter in the Download file.

    Source:papipsycho
    Published:25 Oct 2005
    7.5
    High

    CVE-2005-3304

    Last Modified: 8 Apr 2014

    Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the description parameter in the Web_Links module.

    Source:Sina Yazdanmehr
    Published:25 Oct 2005
    7.3
    High

    CVE-2005-3302

    Last Modified: 21 Aug 2013

    Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

    Source:Joxean Koret
    Published:24 Oct 2005