4.3
    Medium

    CVE-2005-0870

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.

    Source:Maksymilian Arciemowicz
    Published:26 Mar 2005
    4.3
    Medium

    CVE-2005-0863

    Last Modified: 6 May 2013

    Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.

    Source:PersianHacker Team
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0862

    Last Modified: 6 May 2013

    Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php, or (6) yabbse/poc.php, or (7) the sourcedir parameter to yabbse/poc.php.

    Source:Albania Security Clan
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0860

    Last Modified: 6 May 2013

    PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.

    Source:Frank_Reiner
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0859

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of the original vulnerability report. Also, the news.php version was later reported to be in 1.12 through 1.14.

    Source:brOmstar
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0858

    Last Modified: 6 May 2013

    Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.

    Source:Romano
    Published:24 Mar 2005
    4.3
    Medium

    CVE-2005-0857

    Last Modified: 6 May 2013

    Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

    Source:Romano
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0854

    Last Modified: 6 May 2013

    betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.

    Source:farhad koosha
    Published:24 Mar 2005
    5
    Medium

    CVE-2005-0853

    Last Modified: 6 May 2013

    betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.

    Source:farhad koosha
    Published:24 Mar 2005
    2.1
    Low

    CVE-2005-0852

    Last Modified: 6 May 2013

    Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.

    Published:24 Mar 2005
    5
    Medium

    CVE-2005-0848

    Last Modified: 13 May 2013

    Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has arrived using the socket ioctl.

    Source:Luigi Auriemma
    Published:24 Mar 2005
    5
    Medium

    CVE-2005-0847

    Last Modified: 16 Apr 2026

    Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

    Source:GSS IT
    Published:24 Mar 2005
    5
    Medium

    CVE-2005-0843

    Last Modified: 6 May 2013

    CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.

    Source:Alexander Anisimov
    Published:24 Mar 2005
    4.3
    Medium

    CVE-2005-0842

    Last Modified: 5 Jan 2018

    Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.

    Source:GulfTech Security
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0841

    Last Modified: 6 May 2016

    SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via (1) the person parameter to people.php or (2) the Login field.

    Source:kre0n
    Published:24 Mar 2005
    7.5
    High

    CVE-2005-0838

    Last Modified: 6 May 2013

    Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.

    Source:patrick
    Published:22 Mar 2005
    4.3
    Medium

    CVE-2005-0829

    Last Modified: 22 Nov 2016

    Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.

    Source:PersianHacker Team
    Published:22 Mar 2005
    5
    Medium

    CVE-2005-0828

    Last Modified: 6 May 2013

    highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP files by specifying the pathname in the file parameter, as demonstrated by reading database configuration information from mainfile.php.

    Source:Majid NT
    Published:22 Mar 2005
    4.6
    Medium

    CVE-2005-0823

    Last Modified: 16 Apr 2026

    ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.

    Source:Kozan
    Published:20 Mar 2005
    4.3
    Medium

    CVE-2005-0818

    Last Modified: 14 Nov 2016

    Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.

    Source:benji lemien
    Published:20 Mar 2005
    6.4
    Medium

    CVE-2005-0815

    Last Modified: 6 May 2013

    Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.

    Source:Michal Zalewski
    Published:17 Mar 2005
    7.5
    High

    CVE-2005-0805

    Last Modified: 6 May 2013

    SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly handled by imagegallery.php.

    Source:GHC team
    Published:20 Mar 2005
    5
    Medium

    CVE-2005-0804

    Last Modified: 16 Apr 2026

    Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.

    Source:Tal Zeltzer
    Published:20 Mar 2005
    5
    Medium

    CVE-2005-0803

    Last Modified: 16 Apr 2026

    The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."

    Source:Winny Thomas
    Published:20 Mar 2005
    4.3
    Medium

    CVE-2005-0802

    Last Modified: 6 May 2013

    Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.

    Source:farhad koosha
    Published:20 Mar 2005
    7.5
    High

    CVE-2005-0800

    Last Modified: 6 May 2013

    PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

    Source:Jonathan Whiteley
    Published:20 Mar 2005
    5
    Medium

    CVE-2005-0796

    Last Modified: 5 May 2013

    Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

    Source:Virginity Security
    Published:20 Mar 2005
    5
    Medium

    CVE-2005-0795

    Last Modified: 5 May 2013

    HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.

    Source:Virginity Security
    Published:14 Mar 2005
    7.5
    High

    CVE-2005-0792

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.

    Source:Mikhail
    Published:15 Mar 2005
    4.3
    Medium

    CVE-2005-0791

    Last Modified: 6 May 2013

    Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.

    Source:Maksymilian Arciemowicz
    Published:14 Mar 2005
    5
    Medium

    CVE-2005-0788

    Last Modified: 22 Nov 2017

    LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.

    Source:lammat
    Published:14 Mar 2005
    7.5
    High

    CVE-2005-0786

    Last Modified: 5 May 2013

    SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.

    Source:visus
    Published:14 Mar 2005
    4.3
    Medium

    CVE-2005-0783

    Last Modified: 5 May 2013

    Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.

    Source:Jon Oberheide
    Published:20 Mar 2005
    4.3
    Medium

    CVE-2005-0782

    Last Modified: 5 May 2013

    Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.

    Published:20 Mar 2005
    7.5
    High

    CVE-2005-0781

    Last Modified: 5 May 2013

    SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.

    Published:20 Mar 2005
    5
    Medium

    CVE-2005-0780

    Last Modified: 15 Mar 2013

    paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.

    Source:y3dips
    Published:12 Mar 2005
    5
    Medium

    CVE-2005-0779

    Last Modified: 5 May 2013

    PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.

    Source:ports
    Published:20 Mar 2005
    5
    Medium

    CVE-2005-0776

    Last Modified: 2 Jan 2017

    adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.

    Source:Igor Franchuk
    Published:20 Mar 2005
    7.5
    High

    CVE-2005-0773

    Last Modified: 6 Mar 2011

    Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.

    Source:Metasploit
    Published:18 Jun 2005
    10
    Critical

    CVE-2005-0768

    Last Modified: 16 Apr 2026

    Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.

    Source:Komrade
    Published:18 Mar 2005
    7.2
    High

    CVE-2005-0750

    Last Modified: 7 Mar 2019

    The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.

    Source:ilja van sprundel
    Published:24 Mar 2005
    4.3
    Medium

    CVE-2005-0741

    Last Modified: 4 May 2013

    Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.

    Source:trueend5
    Published:8 Mar 2005
    5
    Medium

    CVE-2005-0739

    Last Modified: 28 Apr 2016

    The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and pduval_to_str functions.

    Source:Leon Juranic
    Published:11 Mar 2005
    7.5
    High

    CVE-2005-0737

    Last Modified: 6 May 2013

    Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.

    Source:Mehrtash Mallahzadeh
    Published:13 Mar 2005
    2.1
    Low

    CVE-2005-0736

    Last Modified: 15 Apr 2017

    Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.

    Source:alert7
    Published:9 Mar 2005
    10
    Critical

    CVE-2005-0735

    Last Modified: 4 May 2013

    newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.

    Published:13 Mar 2005
    5
    Medium

    CVE-2005-0731

    Last Modified: 5 May 2013

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.

    Source:Sowhat
    Published:10 Mar 2005
    7.5
    High

    CVE-2005-0725

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.

    Source:ajann
    Published:8 Mar 2005
    7.5
    High

    CVE-2005-0720

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.

    Source:Filip Groszynski
    Published:8 Mar 2005
    7.2
    High

    CVE-2005-0716

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.

    Source:Kevin Finisterre
    Published:21 Mar 2005