LiveActive security incident?Get immediate response
CVE archive

2005 CVE Archive

Browse CVE records published in 2005 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 4627 matching CVEs · Page 4 of 93.

Unknown · CVSS Not scored

CVE-2005-1960: The getemails function in C.J.

The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username.

Published Jun 14, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-1440: Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers t...

Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as demonstrated using forum_new_thread.php and forum_thread.php, (3) the page parameter to page.php, (4) category_id and item_id parameters to reviews.php, (5) the category_id parameter to product_details.php, (6) the category_id or search_string parameters to products.php, or (7) the rp or page parameters to news_view.php.

Published May 3, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-3165: Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inj...

Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.

Published Oct 6, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-4856: The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 2005...

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

Published Jul 6, 2007 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-4787: Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpin...

Turnkey Web Tools SunShop Shopping Cart allows remote attackers to obtain sensitive information via a phpinfo action to (1) index.php, (2) admin/index.php, and (3) admin/adminindex.php, which executes the PHP phpinfo function. NOTE: The vendor has disputed this issue, saying that "Having this in the code makes it easier for us to troubleshoot when issues arise on individual carts. For someone to have a script to do this type of search would require that they know where your shop is actually located. I dont think it really can be construde [sic] as a security issue.

Published Apr 21, 2006 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-4852: The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-al...

The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (underscore), which allows remote attackers to bypass access restrictions by inserting certain characters in a URI, as demonstrated by a request for /admin:de, which matches a rule allowing only /admin_de to access /admin.

Published Jul 6, 2007 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-4765: BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblog...

BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration server, which might allow remote attackers to sniff the connection.

Published Apr 1, 2006 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-3667: Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange versi...

Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable. In addition, since "denial of service" is an impact and not a vulnerability, it is unknown which underlying vulnerabilities are actually covered by this particular candidate.

Published Nov 18, 2005 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2005-1657: Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform...

Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5) Message.Command parameter to messages.ctml.

Published May 18, 2005 · Updated Sep 17, 2024