7.5
    High

    CVE-2005-1506

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in out.php in CJ Ultra (CJUltra) Plus 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via the perm parameter.

    Source:Kold
    Published:11 May 2005
    7.5
    High

    CVE-2005-1503

    Last Modified: 22 May 2013

    Multiple SQL injection vulnerabilities in MidiCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) searchstring parameter to search_list.php, the (2) maingroup or (3) secondgroup parameters to item_list.php, or (4) code_no parameter to item_show.php.

    Source:Exoduks
    Published:11 May 2005
    7.5
    High

    CVE-2005-1500

    Last Modified: 13 May 2016

    Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php. NOTE: item (1) was discovered to affect 2.1.3 as well.

    Source:Alberto Trivero
    Published:11 May 2005
    4.3
    Medium

    CVE-2005-1498

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message. NOTE: issues 2, 3, and 4 may be due to a problem in associated products rather than myBloggie itself.

    Source:Alberto Trivero
    Published:11 May 2005
    4.3
    Medium

    CVE-2005-1494

    Last Modified: 22 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.

    Source:Spy Hat
    Published:11 May 2005
    5
    Medium

    CVE-2005-1493

    Last Modified: 21 May 2013

    Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.

    Source:Donato Ferrante
    Published:11 May 2005
    4.3
    Medium

    CVE-2005-1492

    Last Modified: 21 May 2013

    Cross-site scripting (XSS) vulnerability in user.cgi in Gossamer Threads Links SQL 2.x and 3.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Source:Nathan House
    Published:11 May 2005
    7.5
    High

    CVE-2005-1487

    Last Modified: 21 May 2013

    Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable

    Source:Dcrab
    Published:11 May 2005
    5
    Medium

    CVE-2005-1486

    Last Modified: 21 May 2013

    Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed. The original researcher is known to be unreliable.

    Source:Dcrab
    Published:11 May 2005
    5
    Medium

    CVE-2005-1480

    Last Modified: 16 May 2013

    Directory traversal vulnerability in RaidenFTPD before 2.4.2241 allows remote attackers to read arbitrary files via a "..\\" (dot dot backslash) in the urlget site command.

    Source:Lachlan. H
    Published:11 May 2005
    7.5
    High

    CVE-2005-1479

    Last Modified: 20 May 2013

    SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published:11 May 2005
    5.1
    Medium

    CVE-2005-1477

    Last Modified: 14 Sept 2016

    The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

    Source:Edward Gagnon
    Published:8 May 2005
    5.1
    Medium

    CVE-2005-1476

    Last Modified: 14 Sept 2016

    Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.

    Source:Edward Gagnon
    Published:8 May 2005
    5
    Medium

    CVE-2005-1470

    Last Modified: 13 May 2016

    Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.

    Source:Nicob
    Published:4 May 2005
    7.5
    High

    CVE-2005-1461

    Last Modified: 13 May 2016

    Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.

    Source:Team W00dp3ck3r
    Published:4 May 2005
    6.8
    Medium

    CVE-2005-1440

    Last Modified: 20 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

    Source:Lostmon
    Published:3 May 2005
    2.1
    Low

    CVE-2005-1424

    Last Modified: 16 Apr 2026

    StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.

    Source:Kozan
    Published:3 May 2005
    6.4
    Medium

    CVE-2005-1423

    Last Modified: 22 May 2013

    Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

    Source:dr_insane
    Published:3 May 2005
    4.6
    Medium

    CVE-2005-1418

    Last Modified: 16 Apr 2026

    NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.

    Source:Kozan
    Published:3 May 2005
    7.5
    High

    CVE-2005-1417

    Last Modified: 20 May 2013

    Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7) links_rate.asp, (8) pic_rates.asp, (9) article_toprated.asp, (10) dl_toprated.asp, (11) links_toprated.asp, (12) arguments to pic_toprated.asp, or (13) the TOPIC_ID or Forum_ID parameters to custom_link.asp.

    Source:s-dalili
    Published:3 May 2005
    10
    Critical

    CVE-2005-1415

    Last Modified: 28 Apr 2011

    Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.

    Source:Metasploit
    Published:3 May 2005
    4.6
    Medium

    CVE-2005-1414

    Last Modified: 16 Apr 2026

    ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.

    Source:Kozan
    Published:3 May 2005
    7.5
    High

    CVE-2005-1413

    Last Modified: 15 Dec 2013

    Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to default.asp.

    Source:durito
    Published:3 May 2005
    7.5
    High

    CVE-2005-1412

    Last Modified: 15 May 2013

    SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.

    Source:c0d3r
    Published:3 May 2005
    4.6
    Medium

    CVE-2005-1411

    Last Modified: 16 Apr 2026

    Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.

    Source:Kozan
    Published:3 May 2005
    6.8
    Medium

    CVE-2005-1403

    Last Modified: 20 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.

    Source:Lostmon
    Published:3 May 2005
    5
    Medium

    CVE-2005-1402

    Last Modified: 28 May 2013

    Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

    Source:Luigi Auriemma
    Published:3 May 2005
    7.5
    High

    CVE-2005-1401

    Last Modified: 28 May 2013

    Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.

    Source:Luigi Auriemma
    Published:3 May 2005
    5
    Medium

    CVE-2005-1398

    Last Modified: 19 May 2013

    phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.

    Source:Lostmon
    Published:2 May 2005
    1.2
    Low

    CVE-2005-1396

    Last Modified: 16 Apr 2026

    Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

    Source:Kevin Finisterre
    Published:2 May 2005
    7.2
    High

    CVE-2005-1394

    Last Modified: 16 Apr 2026

    Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

    Source:Kevin Finisterre
    Published:2 May 2005
    7.5
    High

    CVE-2005-1384

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.

    Source:Dcrab
    Published:2 May 2005
    7.5
    High

    CVE-2005-1383

    Last Modified: 19 May 2013

    The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.

    Source:Alexander Kornbrust
    Published:2 May 2005
    5
    Medium

    CVE-2005-1382

    Last Modified: 20 May 2013

    The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.

    Source:Alexander Kornbrust
    Published:2 May 2005
    6.8
    Medium

    CVE-2005-1381

    Last Modified: 20 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.

    Source:Alexander Kornbrust
    Published:2 May 2005
    6.8
    Medium

    CVE-2005-1380

    Last Modified: 19 May 2013

    Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.

    Source:Alexander Kornbrust
    Published:2 May 2005
    7.5
    High

    CVE-2005-1378

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.

    Source:GulfTech Security
    Published:2 May 2005
    7.5
    High

    CVE-2005-1375

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.

    Source:Sieg Fried
    Published:2 May 2005
    6.8
    Medium

    CVE-2005-1374

    Last Modified: 19 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.

    Source:Sieg Fried
    Published:2 May 2005
    4.6
    Medium

    CVE-2005-1372

    Last Modified: 16 Apr 2026

    nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.

    Source:Reed Arvin
    Published:2 May 2005
    7.2
    High

    CVE-2005-1371

    Last Modified: 28 Apr 2011

    BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.

    Source:Jerome Athias
    Published:2 May 2005
    7.5
    High

    CVE-2005-1370

    Last Modified: 19 May 2013

    Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.

    Source:David Morgan
    Published:2 May 2005
    7.5
    High

    CVE-2005-1366

    Last Modified: 23 May 2013

    Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL.

    Source:Claus R. F. Overbeck
    Published:16 May 2005
    10
    Critical

    CVE-2005-1365

    Last Modified: 23 May 2013

    Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.

    Source:Claus R. F. Overbeck
    Published:16 May 2005
    7.5
    High

    CVE-2005-1360

    Last Modified: 18 May 2013

    PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix parameter to reference a URL on a remote web server that contains the code.

    Source:Kold
    Published:28 Apr 2005
    7.5
    High

    CVE-2005-1349

    Last Modified: 19 May 2013

    Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.

    Source:CorryL
    Published:28 Apr 2005
    7.5
    High

    CVE-2005-1348

    Last Modified: 9 Mar 2011

    Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.

    Source:Metasploit
    Published:28 Apr 2005
    7.5
    High

    CVE-2005-1344

    Last Modified: 22 May 2013

    Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.

    Source:Luca Ercoli
    Published:27 Apr 2005
    5
    Medium

    CVE-2005-1333

    Last Modified: 28 May 2013

    Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.

    Source:Kevin Finisterre
    Published:4 May 2005
    5
    Medium

    CVE-2005-1329

    Last Modified: 18 May 2013

    owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.

    Source:Lostmon
    Published:27 Apr 2005