5
    Medium

    CVE-2005-2085

    Last Modified: 16 Apr 2026

    Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.

    Source:Reed Arvin
    Published:30 Jun 2005
    5
    Medium

    CVE-2005-2083

    Last Modified: 16 Apr 2026

    Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.

    Source:Reed Arvin
    Published:30 Jun 2005
    2.1
    Low

    CVE-2005-2078

    Last Modified: 3 Jun 2013

    BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.

    Source:fRoGGz
    Published:29 Jun 2005
    4.3
    Medium

    CVE-2005-2077

    Last Modified: 3 Jun 2013

    Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Source:Ashiyane Digital Security Team
    Published:29 Jun 2005
    5
    Medium

    CVE-2005-2075

    Last Modified: 16 Apr 2026

    PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.

    Source:Easyex
    Published:29 Jun 2005
    7.2
    High

    CVE-2005-2072

    Last Modified: 16 Apr 2026

    The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.

    Source:Przemyslaw Frasunek
    Published:29 Jun 2005
    4.6
    Medium

    CVE-2005-2071

    Last Modified: 3 Jun 2013

    traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).

    Source:Przemyslaw Frasunek
    Published:29 Jun 2005
    7.5
    High

    CVE-2005-2067

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

    Source:mh_p0rtal
    Published:28 Jun 2005
    7.5
    High

    CVE-2005-2066

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.

    Source:Alberto Trivero
    Published:28 Jun 2005
    5
    Medium

    CVE-2005-2065

    Last Modified: 3 Jun 2013

    HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.

    Source:Alberto Trivero
    Published:28 Jun 2005
    5
    Medium

    CVE-2005-2064

    Last Modified: 3 Jun 2013

    Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.

    Source:Alberto Trivero
    Published:28 Jun 2005
    7.5
    High

    CVE-2005-2062

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.

    Source:R3d-D3V!L
    Published:28 Jun 2005
    7.5
    High

    CVE-2005-2058

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.

    Source:GulfTech Security
    Published:28 Jun 2005
    7.5
    High

    CVE-2005-2049

    Last Modified: 1 Jun 2013

    Multiple SQL injection vulnerabilities in DUware DUclassmate 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) iState parameter to default.asp or (2) iPro parameter to edit.asp.

    Source:Dedi Dwianto
    Published:22 Jun 2005
    7.5
    High

    CVE-2005-2048

    Last Modified: 1 Jun 2013

    Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later reported to affect version 3.0.

    Source:Dedi Dwianto
    Published:22 Jun 2005
    7.5
    High

    CVE-2005-2046

    Last Modified: 1 Jun 2013

    Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.

    Source:Dedi Dwianto
    Published:22 Jun 2005
    4.3
    Medium

    CVE-2005-2044

    Last Modified: 24 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5) search, (6) words, (7) include, (8) find_in, (9) display_as, or (10) search parameter to search.php, the (11) submit, (12) query, or (13) field parameter to tile.php, the (14) us parameter to forum/subscribe_forum.php, or the (15) roles[], (16) status, (17) submit, or (18) reset_filter parameters to directory.php.

    Source:Lostmon
    Published:16 Jun 2005
    5
    Medium

    CVE-2005-2041

    Last Modified: 16 Apr 2026

    Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).

    Source:Kevin Finisterre
    Published:15 Jun 2005
    7.5
    High

    CVE-2005-2035

    Last Modified: 30 May 2013

    SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

    Source:Morning Wood
    Published:16 Jun 2005
    5
    Medium

    CVE-2005-2033

    Last Modified: 1 Jun 2013

    Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.

    Source:Seyed Hamid Kashfi
    Published:20 Jun 2005
    5
    Medium

    CVE-2005-2030

    Last Modified: 30 May 2013

    Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.

    Source:Alberto Trivero
    Published:16 Jun 2005
    7.5
    High

    CVE-2005-2028

    Last Modified: 20 May 2016

    SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

    Source:RusH
    Published:21 Jun 2005
    4.3
    Medium

    CVE-2005-2021

    Last Modified: 30 May 2013

    Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.

    Published:20 Jun 2005
    7.5
    High

    CVE-2005-2012

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.

    Source:GulfTech Security
    Published:20 Jun 2005
    4.3
    Medium

    CVE-2005-2011

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.

    Source:GulfTech Security
    Published:20 Jun 2005
    4.3
    Medium

    CVE-2005-2010

    Last Modified: 30 May 2013

    Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.

    Source:Dedi Dwianto
    Published:20 Jun 2005
    7.5
    High

    CVE-2005-2009

    Last Modified: 30 May 2013

    Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.

    Source:Dedi Dwianto
    Published:20 Jun 2005
    5
    Medium

    CVE-2005-2006

    Last Modified: 11 Jul 2017

    JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.

    Source:Marc Schoenefeld
    Published:17 Jun 2005
    7.5
    High

    CVE-2005-2002

    Last Modified: 20 May 2016

    SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.

    Source:pokleyzz
    Published:15 Jun 2005
    7.5
    High

    CVE-2005-2000

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.

    Source:Alpha_Programmer
    Published:15 Jun 2005
    5
    Medium

    CVE-2005-1998

    Last Modified: 30 May 2013

    Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Source:D_BuG
    Published:15 Jun 2005
    5.1
    Medium

    CVE-2005-1990

    Last Modified: 16 Apr 2026

    Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.

    Source:FrSIRT
    Published:10 Aug 2005
    7.5
    High

    CVE-2005-1989

    Last Modified: 16 Apr 2026

    Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".

    Source:FrSIRT
    Published:10 Aug 2005
    5.1
    Medium

    CVE-2005-1988

    Last Modified: 12 Jun 2013

    Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".

    Source:Michal Zalewski
    Published:10 Aug 2005
    10
    Critical

    CVE-2005-1983

    Last Modified: 7 Mar 2011

    Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.

    Source:Metasploit
    Published:10 Aug 2005
    5
    Medium

    CVE-2005-1980

    Last Modified: 16 Apr 2026

    Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."

    Source:Swan
    Published:11 Oct 2005
    5
    Medium

    CVE-2005-1979

    Last Modified: 21 Jun 2013

    Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.

    Source:anonymous
    Published:11 Oct 2005
    7.5
    High

    CVE-2005-1978

    Last Modified: 16 Apr 2026

    COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

    Source:Swan
    Published:11 Oct 2005
    7.5
    High

    CVE-2005-1967

    Last Modified: 29 May 2013

    Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.

    Source:Dedi Dwianto
    Published:14 Jun 2005
    7.5
    High

    CVE-2005-1959

    Last Modified: 30 May 2013

    jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.

    Source:blahplok
    Published:12 Jun 2005
    4.3
    Medium

    CVE-2005-1955

    Last Modified: 30 May 2013

    Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.

    Source:TheGreatOne2176
    Published:12 Jun 2005
    5
    Medium

    CVE-2005-1951

    Last Modified: 5 Jan 2018

    Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php or (3) goto parameter to banner.php.

    Source:GulfTech Security
    Published:14 Jun 2005
    7.5
    High

    CVE-2005-1950

    Last Modified: 14 Sept 2016

    hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

    Source:Alpha_Programmer
    Published:9 Jun 2005
    7.5
    High

    CVE-2005-1948

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.

    Source:GulfTech Security
    Published:9 Jun 2005
    7.5
    High

    CVE-2005-1943

    Last Modified: 29 May 2013

    Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.

    Source:hack_912
    Published:8 Jun 2005
    5
    Medium

    CVE-2005-1939

    Last Modified: 26 Jun 2013

    Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022).

    Source:Dennis Rand
    Published:31 Dec 2005
    5
    Medium

    CVE-2005-1931

    Last Modified: 16 Apr 2026

    GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.

    Source:Reed Arvin
    Published:30 Jun 2005
    9.3
    Critical

    CVE-2005-1924

    Last Modified: 27 Oct 2016

    The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the fpr parameter to the deleteKey function in gpg_keyring.php, as called by (a) import_key_file.php, (b) import_key_text.php, and (c) keyring_main.php; and (2) the keyserver parameter to the gpg_recv_key function in gpg_key_functions.php, as called by gpg_options.php. NOTE: this issue may overlap CVE-2007-3636.

    Source:Backdoored
    Published:31 Dec 2005
    7.5
    High

    CVE-2005-1921

    Last Modified: 19 Jan 2018

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

    Source:GulfTech Security
    Published:29 Jun 2005
    7.2
    High

    CVE-2005-1905

    Last Modified: 16 Apr 2026

    The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.

    Source:Ilya Rabinovich
    Published:8 Jun 2005