LiveActive security incident?Get immediate response
CVE archive

February 2005

Browse CVE records published in February 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 461 matching CVEs · Page 5 of 10.

Unknown · CVSS Not scored

CVE-2005-0409: CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, whi...

CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit card data, and facilitates the exploitation of other vulnerabilities.

Published Feb 16, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0413: Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL c...

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

Published Feb 14, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0366: The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (C...

The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.

Published Feb 11, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0380: Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php,...

Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains the code.

Published Feb 13, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-0367: Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated use...

Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the /msg, /delete, /folderadd, and /folderdelete operations for the Folder parameter.

Published Feb 11, 2005 · Updated Aug 7, 2024