LiveActive security incident?Get immediate response
CVE archive

June 2005

Browse CVE records published in June 2005, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 318 matching CVEs · Page 3 of 7.

Unknown · CVSS Not scored

CVE-2005-2062: Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary...

Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.

Published Jun 28, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2053: Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information v...

Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message. NOTE: a followup suggests that this may be a directory traversal or file inclusion vulnerability.

Published Jun 26, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2064: Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary w...

Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.

Published Jun 28, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2075: PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root wit...

PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.

Published Jun 29, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2048: Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote att...

Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later reported to affect version 3.0.

Published Jun 22, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2046: Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute...

Multiple SQL injection vulnerabilities in DUware DUamazon Pro 3.0 and 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iSub parameter to sub.asp, (3) iSub parameter to detail.asp, (4) iPro parameter to review.asp, iCat parameter to (5) catEdit.asp, (6) catDelete.asp, (7) productEdit.asp, or (8) productDelete.asp, or (9) iType parameter to type.asp.

Published Jun 22, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2057: Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote a...

Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to showprofile.php, (8) fpart or (9) page parameter to showflat.php, or (10) like parameter to showmembers.php.

Published Jun 28, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2045: Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbit...

Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to members_listing_approval.asp, or (6) iChannel parameter to channels_edit.asp.

Published Jun 22, 2005 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2005-2000: Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitr...

Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.

Published Jun 20, 2005 · Updated Aug 7, 2024