Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29935 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2014 1 Php Arena 1 Pafaq 2026-06-16 4.6 MEDIUM N/A
The "upload a language pack" feature in paFAQ 1.0 Beta 4 allows remote authenticated administrators to execute arbitrary PHP commands by uploading a malicious language pack.
CVE-2005-2013 1 Php Arena 1 Pafaq 2026-06-16 5.0 MEDIUM N/A
paFAQ 1.0 Beta 4 allows remote attackers to obtain sensitive information via a direct request to admin/backup.php, which contains a backup of the database including usernames and passwords.
CVE-2005-2012 1 Php Arena 1 Pafaq 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) id parameters.
CVE-2005-2011 1 Php Arena 1 Pafaq 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Question action.
CVE-2005-2010 1 Uapplication 1 Ublog Reload 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.
CVE-2005-2009 1 Ublog 1 Reload 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.
CVE-2005-2008 1 Yaws 1 Webserver 2026-06-16 5.0 MEDIUM N/A
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
CVE-2005-2007 1 Edgewall Software 1 Trac 2026-06-16 6.4 MEDIUM N/A
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
CVE-2005-2006 1 Jboss 1 Jboss 2026-06-16 5.0 MEDIUM N/A
JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the file.
CVE-2005-2005 1 Ultimate Php Board 1 Ultimate Php Board 2026-06-16 5.0 MEDIUM N/A
Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.
CVE-2005-2004 1 Ultimate Php Board 1 Ultimate Php Board 2026-06-16 5.0 MEDIUM N/A
Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, (2) id or (3) page parameter to viewtopic.php, id parameter to (4) profile.php, (5) newpost.php, (6) email.php, (7) icq.php, or (8) aol.php, (9) t_id parameter to newpost.php, (10) ref parameter to getpass.php, or (11) sText parameter to search.php.
CVE-2005-2003 1 Ultimate Php Board 1 Ultimate Php Board 2026-06-16 5.0 MEDIUM N/A
Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.
CVE-2005-2002 1 Mambo 1 Mambo 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.
CVE-2005-2001 1 Php Arena 1 Pafiledb 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.
CVE-2005-2000 1 Php Arena 1 Pafiledb 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.
CVE-2005-1999 1 Php Arena 1 Pafiledb 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).
CVE-2005-1998 1 Mcgallery 1 Mcgallery 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
CVE-2005-1997 1 Mcgallery 1 Mcgallery 2026-06-16 5.0 MEDIUM N/A
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.
CVE-2005-1995 1 Bitrix 1 Bitrix Site Manager 2026-06-16 5.0 MEDIUM N/A
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.
CVE-2005-1994 1 Finjan Software 1 Surfingate 2026-06-16 5.0 MEDIUM N/A
Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using "%2e".