5.8
    Medium

    CVE-2005-1162

    Last Modified: 14 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.

    Source:Dcrab
    Published:18 Apr 2005
    7.5
    High

    CVE-2005-1161

    Last Modified: 14 May 2013

    Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp.

    Source:Dcrab
    Published:18 Apr 2005
    7.5
    High

    CVE-2005-1149

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

    Source:LaMeR
    Published:13 Apr 2005
    4.3
    Medium

    CVE-2005-1135

    Last Modified: 14 May 2013

    Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:y3dips
    Published:16 Apr 2005
    7.5
    High

    CVE-2005-1134

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.

    Source:kre0n
    Published:13 Apr 2005
    4.3
    Medium

    CVE-2005-1130

    Last Modified: 13 May 2013

    Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.

    Source:SmOk3
    Published:12 Apr 2005
    5.1
    Medium

    CVE-2005-1125

    Last Modified: 14 May 2013

    Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.

    Source:Overflow.pl
    Published:16 Apr 2005
    4.3
    Medium

    CVE-2005-1118

    Last Modified: 14 May 2013

    Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.

    Source:Oliver Karow
    Published:14 Apr 2005
    7.5
    High

    CVE-2005-1117

    Last Modified: 14 May 2013

    PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code.

    Source:Francisco Alisson
    Published:16 Apr 2005
    5
    Medium

    CVE-2005-1112

    Last Modified: 14 May 2013

    IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.

    Source:SPI Labs
    Published:16 Apr 2005
    7.5
    High

    CVE-2005-1110

    Last Modified: 6 May 2016

    Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attackers to execute arbitrary code via a large packet sent to TCP port 81.

    Source:vade79
    Published:16 Apr 2005
    5
    Medium

    CVE-2005-1105

    Last Modified: 13 May 2013

    Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.

    Source:Rafael San Miguel Carrasco
    Published:13 Apr 2005
    7.5
    High

    CVE-2005-1100

    Last Modified: 6 May 2016

    Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.

    Source:Xpl017Elz
    Published:13 Apr 2005
    10
    Critical

    CVE-2005-1099

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.

    Source:Metasploit
    Published:12 Apr 2005
    2.1
    Low

    CVE-2005-1098

    Last Modified: 22 Nov 2017

    GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.

    Source:Kozan
    Published:13 Apr 2005
    4.6
    Medium

    CVE-2005-1097

    Last Modified: 16 Apr 2026

    Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.

    Source:Kozan
    Published:13 Apr 2005
    4.3
    Medium

    CVE-2005-1095

    Last Modified: 11 May 2013

    Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Zinho
    Published:13 Apr 2005
    4.6
    Medium

    CVE-2005-1094

    Last Modified: 16 Apr 2026

    FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

    Source:Kozan
    Published:8 Apr 2005
    7.2
    High

    CVE-2005-1092

    Last Modified: 6 May 2016

    Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

    Source:Kozan
    Published:13 Apr 2005
    6.4
    Medium

    CVE-2005-1087

    Last Modified: 12 May 2013

    CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.

    Source:Tan Chew Keong
    Published:7 Apr 2005
    6.4
    Medium

    CVE-2005-1086

    Last Modified: 12 May 2013

    Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.

    Source:Tan Chew Keong
    Published:13 Apr 2005
    7.5
    High

    CVE-2005-1082

    Last Modified: 12 May 2013

    Multiple SQL injection vulnerabilities in AzDGDatingPlatinum 1.1.0 allows remote attackers to execute arbitrary SQL commands via (1) the id parameter to view.php or (2) the from parameter to members/index.php.

    Source:kre0n
    Published:9 Apr 2005
    4.3
    Medium

    CVE-2005-1081

    Last Modified: 12 May 2013

    Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:kre0n
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-1079

    Last Modified: 12 May 2013

    SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Andreas Constantinides
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-1078

    Last Modified: 13 May 2013

    XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.

    Source:Morning Wood
    Published:12 Apr 2005
    4.3
    Medium

    CVE-2005-1077

    Last Modified: 13 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.

    Source:Morning Wood
    Published:12 Apr 2005
    4.3
    Medium

    CVE-2005-1076

    Last Modified: 12 May 2013

    Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.

    Source:lacertosum
    Published:12 Apr 2005
    4.3
    Medium

    CVE-2005-1075

    Last Modified: 12 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.

    Source:Dcrab
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-1074

    Last Modified: 12 May 2013

    SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

    Source:Dcrab
    Published:12 Apr 2005
    5
    Medium

    CVE-2005-1073

    Last Modified: 12 May 2013

    Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.

    Source:Dcrab
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-1071

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.

    Source:CiNU5
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-1070

    Last Modified: 12 May 2013

    SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter.

    Source:Dcrab
    Published:11 Apr 2005
    5
    Medium

    CVE-2005-1061

    Last Modified: 15 May 2013

    The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."

    Source:anonymous
    Published:28 Oct 2004
    2.1
    Low

    CVE-2005-1059

    Last Modified: 11 May 2013

    Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.

    Source:Kristian Hermansen
    Published:12 Apr 2005
    7.5
    High

    CVE-2005-1054

    Last Modified: 5 Jan 2018

    PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.

    Source:GulfTech Security
    Published:12 Apr 2005
    4.3
    Medium

    CVE-2005-1053

    Last Modified: 5 Jan 2018

    Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.

    Source:GulfTech Security
    Published:12 Apr 2005
    6.5
    Medium

    CVE-2005-1051

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.

    Source:Stefan Esser
    Published:12 Apr 2005
    2.6
    Low

    CVE-2005-1049

    Last Modified: 12 May 2013

    Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for 760 RC3, or for .750. However, the op/user.php issue exists when the pnAntiCracker setting is disabled.

    Source:Dcrab
    Published:12 Apr 2005
    5
    Medium

    CVE-2005-1033

    Last Modified: 11 May 2013

    CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.

    Source:John Cobb
    Published:9 Apr 2005
    Low

    CVE-2005-1032

    Last Modified: 7 Nov 2023

    cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters. NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type and severity. The vendor has disputed this issue, saying "These reports are credited to malicious person we refused to hire. We have not taken legal action against him only because he is located in India. The vulnerabilites reported can not be reproduced, hence information you provide is contrary to fact." Further investigation by CVE personnel shows that an invalid SQL syntax error could be generated, but it only reveals portions of underlying database structure, which is already available in documentation from the vendor, and it does not appear to lead to path disclosure. Therefore, this issue is not a vulnerability or an exposure, and it probably should be REJECTED

    Source:k1tk4t
    Published:6 Apr 2005
    4.3
    Medium

    CVE-2005-1030

    Last Modified: 10 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to watchthisitem.asp.

    Source:Dcrab
    Published:9 Apr 2005
    7.5
    High

    CVE-2005-1029

    Last Modified: 10 May 2013

    Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.

    Source:Dcrab
    Published:6 Apr 2005
    4.3
    Medium

    CVE-2005-1027

    Last Modified: 10 May 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x through 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in the Your_Account module, (2) avatarcategory parameter in the Your_Account module, or (3) lid parameter in the Downloads module.

    Published:9 Apr 2005
    7.5
    High

    CVE-2005-1026

    Last Modified: 10 May 2013

    Multiple SQL injection vulnerabilities in SnailSource phpBB 2.0.x mods allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to dlman.php in DLMan Pro or (2) id parameter to links.php in Linkz Pro (aka LinksLinks Pro).

    Source:LovER BOY
    Published:9 Apr 2005
    4.3
    Medium

    CVE-2005-1023

    Last Modified: 17 Jan 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 6.x to 7.6 allow remote attackers to inject arbitrary web script or HTML via the (1) min parameter to the Search module, (2) the categories parameter to the FAQ module, or (3) the ltr parameter to the Encyclopedia module. NOTE: the bid parameter issue in banners.php is already an item in CVE-2005-1000.

    Source:Janek Vind
    Published:9 Apr 2005
    7.2
    High

    CVE-2005-1019

    Last Modified: 6 May 2016

    Buffer overflow in the getConfig function in Aeon 0.2a and earlier allows local users to gain privileges via a long HOME environment variable.

    Source:lammat
    Published:9 Apr 2005
    7.5
    High

    CVE-2005-1018

    Last Modified: 10 Mar 2011

    Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.

    Source:Metasploit
    Published:12 Apr 2005
    5
    Medium

    CVE-2005-1013

    Last Modified: 16 Apr 2026

    The SMTP service in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to cause a denial of service (server crash) via an EHLO command with a Unicode string.

    Source:CorryL
    Published:8 Apr 2005
    7.5
    High

    CVE-2005-1011

    Last Modified: 10 May 2013

    SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

    Source:Zinho
    Published:8 Apr 2005
    10
    Critical

    CVE-2005-1009

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name entry in the configure.cfg file.

    Source:class101
    Published:8 Apr 2005