4.3
    Medium

    CVE-2005-3301

    Last Modified: 23 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

    Source:Tobias Klein
    Published:24 Oct 2005
    5
    Medium

    CVE-2005-3299

    Last Modified: 7 Jun 2016

    PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

    Source:cXIb8O3
    Published:23 Oct 2005
    5
    Medium

    CVE-2005-3294

    Last Modified: 6 Sept 2010

    Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (crash) by sending multiple RETR commands. NOTE: it was later reported that 1.10 is also affected.

    Source:Jeremiah Talamantes
    Published:23 Oct 2005
    5
    Medium

    CVE-2005-3293

    Last Modified: 23 Jun 2013

    Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.

    Source:Ziv Kamir
    Published:23 Oct 2005
    7.5
    High

    CVE-2005-3290

    Last Modified: 13 Oct 2017

    SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.

    Source:imready4chillin
    Published:23 Oct 2005
    4.3
    Medium

    CVE-2005-3285

    Last Modified: 21 Jun 2013

    Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.

    Source:Lostmon
    Published:23 Oct 2005
    10
    Critical

    CVE-2005-3277

    Last Modified: 16 Apr 2026

    The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.

    Source:H D Moore
    Published:21 Oct 2005
    7.5
    High

    CVE-2005-3262

    Last Modified: 14 May 2018

    Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

    Source:Tan Chew Keong
    Published:20 Oct 2005
    7.5
    High

    CVE-2005-3259

    Last Modified: 18 Jul 2018

    Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in userlistpre.php, and the (6) select, (7) categ, and (8) to parameters in index.php.

    Source:rgod
    Published:20 Oct 2005
    4.6
    Medium

    CVE-2005-3257

    Last Modified: 21 Jun 2013

    The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local users to use the KDSKBSENT ioctl on terminals of other users and gain privileges, as demonstrated by modifying key bindings using loadkeys.

    Source:Rudolf Polzer
    Published:15 Oct 2005
    7.5
    High

    CVE-2005-3252

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.

    Source:KaiJern Lau
    Published:18 Oct 2005
    7.5
    High

    CVE-2005-3243

    Last Modified: 7 Jun 2016

    Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.

    Source:Sowhat
    Published:19 Oct 2005
    4.3
    Medium

    CVE-2005-3237

    Last Modified: 20 Jun 2013

    Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML via the t_login parameter of footer.php.

    Published:14 Oct 2005
    6.8
    Medium

    CVE-2005-3236

    Last Modified: 20 Jun 2013

    Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS attacks when the SQL syntax is invalid or (2) the nick parameter of lostpwd.php.

    Source:rgod
    Published:14 Oct 2005
    6.8
    Medium

    CVE-2005-3208

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.

    Source:farhad koosha
    Published:14 Oct 2005
    5
    Medium

    CVE-2005-3207

    Last Modified: 20 Jun 2013

    The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command.

    Source:Alexander Kornbrust
    Published:14 Oct 2005
    5
    Medium

    CVE-2005-3206

    Last Modified: 7 Oct 2017

    iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command.

    Source:Alexander Kornbrust
    Published:14 Oct 2005
    4.3
    Medium

    CVE-2005-3204

    Last Modified: 20 Jun 2013

    Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.

    Source:Alexander Kornbrust
    Published:14 Oct 2005
    6.8
    Medium

    CVE-2005-3202

    Last Modified: 7 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters.

    Source:Red-Database-Security
    Published:14 Oct 2005
    7.5
    High

    CVE-2005-3201

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.

    Source:rgod
    Published:14 Oct 2005
    4.3
    Medium

    CVE-2005-3200

    Last Modified: 7 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.

    Source:rgod
    Published:14 Oct 2005
    7.5
    High

    CVE-2005-3190

    Last Modified: 10 Oct 2017

    Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows remote attackers to execute arbitrary code via HTTP GET requests.

    Source:egm
    Published:13 Oct 2005
    5
    Medium

    CVE-2005-3189

    Last Modified: 25 May 2017

    Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.

    Source:FistFuXXer
    Published:18 Nov 2005
    5
    Medium

    CVE-2005-3187

    Last Modified: 29 Sept 2016

    The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP request that causes an out-of-bounds read.

    Source:FistFuXXer
    Published:31 Dec 2005
    7.5
    High

    CVE-2005-3159

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.

    Source:almaster
    Published:6 Oct 2005
    7.5
    High

    CVE-2005-3157

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send parameter, a different vulnerability than CVE-2005-3158 and CVE-2005-3159.

    Source:rgod
    Published:6 Oct 2005
    7.5
    High

    CVE-2005-3155

    Last Modified: 10 Mar 2011

    Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.

    Source:Metasploit
    Published:5 Oct 2005
    4.3
    Medium

    CVE-2005-3152

    Last Modified: 19 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect 3.0.7-pl1.

    Source:Lostmon
    Published:5 Oct 2005
    7.5
    High

    CVE-2005-3135

    Last Modified: 16 Apr 2026

    Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename.

    Source:Luigi Auriemma
    Published:4 Oct 2005
    5
    Medium

    CVE-2005-3133

    Last Modified: 19 Jun 2013

    Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.

    Source:ShineShadow
    Published:4 Oct 2005
    4.3
    Medium

    CVE-2005-3131

    Last Modified: 19 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.

    Source:ss_contacts
    Published:4 Oct 2005
    7.5
    High

    CVE-2005-3130

    Last Modified: 19 Jun 2013

    SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.

    Source:rgod
    Published:4 Oct 2005
    4.3
    Medium

    CVE-2005-3128

    Last Modified: 19 Jun 2013

    Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.

    Source:anonymous
    Published:4 Oct 2005
    4.3
    Medium

    CVE-2005-3127

    Last Modified: 19 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:X1ngBox
    Published:4 Oct 2005
    9.8
    Critical

    CVE-2005-3120

    Last Modified: 7 Jun 2016

    Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

    Source:Ulf Harnhammar
    Published:17 Oct 2005
    10
    Critical

    CVE-2005-3116

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet.

    Source:Patrick Thomassen
    Published:18 Nov 2005
    4.6
    Medium

    CVE-2005-3098

    Last Modified: 4 Oct 2017

    poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.

    Source:kingcope
    Published:28 Sept 2005
    4.3
    Medium

    CVE-2005-3083

    Last Modified: 19 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:X1ngBox
    Published:27 Sept 2005
    4.6
    Medium

    CVE-2005-3081

    Last Modified: 7 Jun 2016

    wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command.

    Source:kingcope
    Published:27 Sept 2005
    5
    Medium

    CVE-2005-3077

    Last Modified: 19 Jun 2013

    Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI.

    Source:Mella Marco
    Published:27 Sept 2005
    5
    Medium

    CVE-2005-3064

    Last Modified: 16 Apr 2026

    MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).

    Source:Luigi Auriemma
    Published:27 Sept 2005
    7.5
    High

    CVE-2005-3063

    Last Modified: 18 Jul 2018

    SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page.

    Source:rgod
    Published:27 Sept 2005
    7.5
    High

    CVE-2005-3058

    Last Modified: 30 Jul 2013

    Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.

    Source:Mathieu Dessus
    Published:31 Dec 2005
    7.5
    High

    CVE-2005-3052

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

    Source:krasza
    Published:23 Sept 2005
    6.4
    Medium

    CVE-2005-3048

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file.

    Source:rgod
    Published:23 Sept 2005
    7.5
    High

    CVE-2005-3045

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.

    Source:rgod
    Published:23 Sept 2005
    7.5
    High

    CVE-2005-3043

    Last Modified: 19 Jun 2013

    SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.

    Source:SmOk3
    Published:22 Sept 2005
    5
    Medium

    CVE-2005-3026

    Last Modified: 18 Jun 2013

    Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.

    Source:h4cky0u
    Published:21 Sept 2005
    4.3
    Medium

    CVE-2005-3020

    Last Modified: 18 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.

    Published:21 Sept 2005
    7.5
    High

    CVE-2005-3019

    Last Modified: 18 Jun 2013

    Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.

    Published:21 Sept 2005