Vulnerabilities (CVE)

Total 304758 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2003-0317 1 Iisprotect 1 Iisprotect 2008-10-03 7.5 HIGH N/A
iisPROTECT 2.1 and 2.2 allows remote attackers to bypass authentication via an HTTP request containing URL-encoded characters.
CVE-2002-0470 1 Phpnettoolpack 1 Phpnettoolpack 2008-09-24 7.2 HIGH N/A
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path.
CVE-2002-0471 1 Phpnettoolpack 1 Phpnettoolpack 2008-09-24 10.0 HIGH N/A
PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable.
CVE-2000-0697 1 Sun 1 Solaris Answerbook2 2008-09-24 10.0 HIGH N/A
The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.
CVE-2005-4631 1 Ryan Lath 1 Zina 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.
CVE-2005-4373 1 Liquid Bytes Technologies 1 Adaptive Website Framework 2008-09-20 5.0 MEDIUM N/A
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.
CVE-2005-4410 1 Nqcontent 1 Nqcontent 2008-09-20 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter.
CVE-2005-4429 1 Cs-cart 1 Cs-cart 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in CS-Cart 1.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) sort_by and (2) sort_order parameters to index.php.
CVE-2005-4632 1 Vote Pro 1 Vote Pro 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
CVE-2005-4512 1 Waxtrapp 1 Waxtrapp 2008-09-20 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in WAXTRAPP 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
CVE-2005-4480 1 Plexcor 1 Plexcor Cms 2008-09-20 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
CVE-2005-4651 1 Alstrasoft 1 Epay 2008-09-20 6.4 MEDIUM N/A
SQL injection vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the pmodule parameter.
CVE-2005-4641 1 Eazycms 1 Eazycms 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in home.php in eazyCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
CVE-2005-4621 1 Jelsoft 1 Vbulletin 2008-09-20 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
CVE-2005-4401 1 Lutece 1 Lutece 2008-09-20 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Lutece 1.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the query parameter.
CVE-2005-4619 1 Phpoutsourcing 1 Zorum 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.
CVE-2005-4743 1 Nelogic Technologies 1 Nephp Publisher 2008-09-20 5.0 MEDIUM N/A
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.
CVE-2005-4406 1 Tmc Visionpool 1 Mercury Cms 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVE-2005-4781 1 Sergids 1 Top Music Module 2008-09-20 5.0 MEDIUM N/A
Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php.
CVE-2005-4629 1 Smbcms 1 Smbcms 2008-09-20 7.5 HIGH N/A
SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.