5
    Medium

    CVE-2005-2581

    Last Modified: 16 Apr 2026

    Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060.

    Source:Pierre Kroma
    Published:16 Aug 2005
    7.5
    High

    CVE-2005-2580

    Last Modified: 20 Dec 2016

    Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.

    Source:phuket
    Published:16 Aug 2005
    5
    Medium

    CVE-2005-2577

    Last Modified: 13 Jun 2013

    Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero in the IP option length field.

    Source:Piotr Chytla
    Published:16 Aug 2005
    4.3
    Medium

    CVE-2005-2569

    Last Modified: 11 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername, (7) fmail, (8) www, (9) icq, (10) yim, (11) location, (12) sex, (13) interebbies, (14) sig or (15) aim parameter to register.php, or (16) subject parameter to newtopic.php.

    Source:rgod
    Published:16 Aug 2005
    7.5
    High

    CVE-2005-2564

    Last Modified: 7 Dec 2016

    Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.

    Source:RusH
    Published:16 Aug 2005
    7.5
    High

    CVE-2005-2562

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field.

    Source:rgod
    Published:16 Aug 2005
    4.3
    Medium

    CVE-2005-2560

    Last Modified: 10 Jun 2013

    Cross-site scripting (XSS) vulnerability in index.cfm in CFBB 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:rUnViRuS
    Published:16 Aug 2005
    4.3
    Medium

    CVE-2005-2557

    Last Modified: 8 Jun 2018

    Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

    Source:anonymous
    Published:28 Sept 2005
    7.5
    High

    CVE-2005-2551

    Last Modified: 9 Mar 2011

    Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.

    Source:Metasploit
    Published:12 Aug 2005
    5
    Medium

    CVE-2005-2543

    Last Modified: 11 Jun 2013

    Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.

    Source:anonymous
    Published:10 Aug 2005
    5
    Medium

    CVE-2005-2542

    Last Modified: 8 Jan 2018

    Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.

    Source:V[i]RuS
    Published:10 Aug 2005
    5
    Medium

    CVE-2005-2540

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding comment character, which can then be executed by a direct request.

    Source:rgod
    Published:10 Aug 2005
    4.3
    Medium

    CVE-2005-2539

    Last Modified: 11 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in FlatNuke 2.5.5 and possibly earlier versions allow remote attackers to inject arbitrary web script or HTML via the (1) bodycolor, (2) backimage, (3) theme, or (4) logo parameter to structure.php, (5) admin, (6) admin_mail, or (7) back parameter to footer.php, or (8) the message body in a news post.

    Source:rgod
    Published:10 Aug 2005
    7.5
    High

    CVE-2005-2535

    Last Modified: 16 Apr 2026

    Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260.

    Source:cybertronic
    Published:10 Aug 2005
    4.3
    Medium

    CVE-2005-2523

    Last Modified: 13 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Source:Donnie Werner
    Published:19 Aug 2005
    4.6
    Medium

    CVE-2005-2508

    Last Modified: 14 Jun 2013

    dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.

    Source:Neil Archibald
    Published:19 Aug 2005
    4.3
    Medium

    CVE-2005-2488

    Last Modified: 10 Jun 2013

    Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.

    Source:rgod
    Published:7 Aug 2005
    7.5
    High

    CVE-2005-2486

    Last Modified: 10 Jun 2013

    SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.

    Published:7 Aug 2005
    7.5
    High

    CVE-2005-2483

    Last Modified: 10 Jun 2013

    Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.

    Source:Radovan Garabík
    Published:7 Aug 2005
    4.3
    Medium

    CVE-2005-2480

    Last Modified: 10 Jun 2013

    Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.

    Source:N.N.P
    Published:5 Aug 2005
    5
    Medium

    CVE-2005-2479

    Last Modified: 16 Apr 2026

    Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command.

    Source:Kozan
    Published:5 Aug 2005
    4.3
    Medium

    CVE-2005-2476

    Last Modified: 10 Jun 2013

    Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Source:John Cobb
    Published:5 Aug 2005
    5
    Medium

    CVE-2005-2472

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.

    Source:Reed Arvin
    Published:5 Aug 2005
    6.4
    Medium

    CVE-2005-2468

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or the insert function in (7) releases.php or (8) class.release.php.

    Source:GulfTech Security
    Published:31 Dec 2005
    5.8
    Medium

    CVE-2005-2467

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.

    Source:GulfTech Security
    Published:31 Dec 2005
    6.4
    Medium

    CVE-2005-2466

    Last Modified: 10 Jun 2013

    Multiple SQL injection vulnerabilities in the auth_user function in admin.php in OpenBook 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Source:SVT
    Published:31 Dec 2005
    6.4
    Medium

    CVE-2005-2461

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter.

    Source:GulfTech Security
    Published:31 Dec 2005
    5.8
    Medium

    CVE-2005-2460

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message.

    Source:GulfTech Security
    Published:31 Dec 2005
    5
    Medium

    CVE-2005-2455

    Last Modified: 7 Jun 2013

    Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts using GM_scripts, or obtain sensitive information via (3) GM_setValue and GM_getValue.

    Source:Mark Pilgrim
    Published:4 Aug 2005
    4.3
    Medium

    CVE-2005-2453

    Last Modified: 10 Jun 2013

    Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:Secunia Research
    Published:4 Aug 2005
    4.3
    Medium

    CVE-2005-2441

    Last Modified: 9 Jun 2013

    Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.

    Source:almaster
    Published:3 Aug 2005
    7.5
    High

    CVE-2005-2432

    Last Modified: 9 Jun 2013

    SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.

    Source:tgo
    Published:3 Aug 2005
    5
    Medium

    CVE-2005-2428

    Last Modified: 16 Apr 2026

    Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.

    Source:Marco Ivaldi
    Published:3 Aug 2005
    2.1
    Low

    CVE-2005-2426

    Last Modified: 16 Apr 2026

    FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.

    Source:Reed Arvin
    Published:3 Aug 2005
    10
    Critical

    CVE-2005-2420

    Last Modified: 25 May 2016

    flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.

    Source:newbug
    Published:3 Aug 2005
    2.6
    Low

    CVE-2005-2414

    Last Modified: 19 Jan 2018

    Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.

    Source:GulfTech Security
    Published:3 Aug 2005
    5
    Medium

    CVE-2005-2412

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.

    Source:Dj7xpl
    Published:3 Aug 2005
    7.5
    High

    CVE-2005-2409

    Last Modified: 25 May 2016

    Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

    Source:CoKi
    Published:1 Aug 2005
    4.3
    Medium

    CVE-2005-2397

    Last Modified: 9 Jun 2013

    Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin parameter.

    Source:rgod
    Published:27 Jul 2005
    4.3
    Medium

    CVE-2005-2386

    Last Modified: 9 Jun 2013

    Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:Zinho
    Published:27 Jul 2005
    7.5
    High

    CVE-2005-2383

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.

    Source:GHC
    Published:26 Jul 2005
    7.2
    High

    CVE-2005-2373

    Last Modified: 5 Oct 2017

    Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.

    Source:Metasploit
    Published:26 Jul 2005
    7.5
    High

    CVE-2005-2367

    Last Modified: 25 May 2016

    Format string vulnerability in the proto_item_set_text function in Ethereal 0.9.4 through 0.10.11, as used in multiple dissectors, allows remote attackers to write to arbitrary memory locations and gain privileges via a crafted AFP packet.

    Source:vade79
    Published:27 Jul 2005
    5
    Medium

    CVE-2005-2357

    Last Modified: 11 Jun 2013

    Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Source:anonymous
    Published:16 Aug 2005
    7.5
    High

    CVE-2005-2340

    Last Modified: 5 Aug 2013

    Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.

    Source:Dennis Rand
    Published:31 Dec 2005
    5
    Medium

    CVE-2005-2330

    Last Modified: 7 Jun 2013

    Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.

    Source:Andrew Hunter
    Published:20 Jul 2005
    4.3
    Medium

    CVE-2005-2327

    Last Modified: 25 May 2016

    Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.

    Source:warlord
    Published:20 Jul 2005
    4.3
    Medium

    CVE-2005-2326

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.

    Source:Lostmon
    Published:19 Jul 2005
    4.3
    Medium

    CVE-2005-2324

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype or searchterm parameters to (1) results.php or (2) categorysearch.php.

    Source:Lostmon
    Published:19 Jul 2005
    7.5
    High

    CVE-2005-2323

    Last Modified: 25 May 2016

    Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.

    Source:basher13
    Published:19 Jul 2005