Skip to main content

Year archive

CVEs published in 2005

Archive summary

4,932 CVEs published in 2005 — 322 Critical, 1,739 High, 2,430 Medium, 441 Low, 0 Unrated.

CVE-2005-4479

Published Dec 22, 2005

SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4480

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in Plexcor CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4481

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. NOTE: the vend…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4482

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4483

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in login.asp in SiteEnable 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4484

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in IntranetApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ret_page parameter to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4485

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in ProjectApp 3.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4486

Published Dec 22, 2005

SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly Q-Publishing) allows remote attackers to execute arbitrary SQL commands via the p_news_id parameter to (1) news…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4487

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in RAMSite R|1 CMS 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4488

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in index.tpl in Redakto WCMS 3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) iid, (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4489

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4490

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4491

Published Dec 22, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Sitekit CMS 6.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) text…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4493

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in SpearTek 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4494

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-4495

Published Dec 22, 2005

SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this iss…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4496

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4497

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4498

Published Dec 22, 2005

Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4474

Published Dec 22, 2005

Buffer overflow in the "Add to archive" command in WinRAR 3.51 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by tricking…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4464

Published Dec 22, 2005

Ingate Firewall before 4.3.4 and SIParator before 4.3.4 allows remote attackers to cause a denial of service (kernel deadlock) by sending a SYN packet for a TCP stream, which requ…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4465

Published Dec 22, 2005

The Internet Key Exchange version 1 (IKEv1) implementation in NEC UNIVERGE IX1000, IX2000, and IX3000 allows remote attackers to cause a denial of service and possibly execute arb…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4466

Published Dec 22, 2005

Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly exec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 4,932 CVEsPage 20 of 198