Show filters
536 Total Results
Displaying 511-520 of 536
Sort by:
Attacker Value
Unknown
CVE-2005-4857
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051128 allows remote authenticated users to cause a denial of service (Apache httpd segmentation fault) via a request to content/advancedsearch.php with an empty SearchContentClassID parameter, reportedly related to a "memory addressing error".
0
Attacker Value
Unknown
CVE-2005-4855
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.
0
Attacker Value
Unknown
CVE-2005-4571
Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in myEZshop Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-4572
Disclosure Date: December 29, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-3845
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email support@ezinvoiceinc.com and EZI will email you the patch to fix this small issue."
0
Attacker Value
Unknown
CVE-2005-3834
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in search.php in Tunez 1.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchFor parameter.
0
Attacker Value
Unknown
CVE-2005-3833
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
SQL injection vulnerability in songinfo.php in Tunez 1.21 and earlier allows remote attackers to execute arbitrary SQL commands via the song_id parameter.
0
Attacker Value
Unknown
CVE-2005-3826
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
0
Attacker Value
Unknown
CVE-2005-3589
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
0
Attacker Value
Unknown
CVE-2005-2898
Disclosure Date: September 14, 2005 (last updated February 22, 2025)
NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when "Use secure mode" is disabled, uses a weak encryption scheme to store the user's password in the configuration settings file, which allows local users to obtain sensitive information. NOTE: the vendor has disputed the issue, stating that "the problem is not a vulnerability at all, but in fact a fundamental issue of every single program that can store passwords transparently.
0