CVE Database - 2005

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

192
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2005-3283

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-3288

MEDIUM
5.00 CVSS 2.0

Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.

Unrestricted File Upload
WAF: Medium

CVE-2005-3205

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-3183

MEDIUM
4.30 CVSS 2.0

The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.

Improper Input Validation
WAF: Medium

CVE-2005-3055

LOW
2.10 CVSS 2.0

Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.

Improper Input Validation
WAF: Medium

CVE-2005-3046

MEDIUM
6.80 CVSS 2.0

SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

SQL Injection
WAF: High

CVE-2005-3047

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-2703

MEDIUM
5.00 CVSS 2.0

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

Code Injection
WAF: Medium

CVE-2005-2981

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-2983

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.

SQL Injection
WAF: High

CVE-2005-2837

HIGH
7.50 CVSS 2.0

Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm.

Code Injection
WAF: Medium

CVE-2005-2818

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-2806

MEDIUM
5.00 CVSS 2.0

client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.

Improper Input Validation
WAF: Medium

CVE-2005-2773

CRITICAL
9.80 CVSS 3.1

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

Command Injection
WAF: High

CVE-2005-2792

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.

Path Traversal
WAF: High

CVE-2005-2793

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

Command Injection
WAF: High

CVE-2005-1527

MEDIUM
5.00 CVSS 2.0

Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.

Code Injection
WAF: Medium

CVE-2005-2498

HIGH
7.50 CVSS 2.0

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

Code Injection
WAF: Medium

CVE-2005-1761

LOW
2.10 CVSS 2.0

Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.

Improper Input Validation
WAF: Medium

CVE-2005-2405

MEDIUM
5.00 CVSS 2.0

Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.

Improper Input Validation
WAF: Medium

CVE-2005-2406

MEDIUM
4.30 CVSS 2.0

Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-2368

HIGH
9.30 CVSS 2.0

vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.

OS Command Injection
WAF: High

CVE-2005-2371

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

Path Traversal
WAF: High

CVE-2005-2378

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.

Path Traversal
WAF: High

CVE-2005-2309

MEDIUM
5.00 CVSS 2.0

Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2005-2254

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there is evidence that viewnews.php and login.php may not be part of the PhpAuction product, so they are not included in this description.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-2177

MEDIUM
5.00 CVSS 2.0

Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.

Improper Input Validation
WAF: Medium

CVE-2005-1921

HIGH
7.50 CVSS 2.0

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

Code Injection
WAF: Medium

CVE-2005-2136

MEDIUM
4.60 CVSS 2.0

Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.

Incorrect Authorization
WAF: Low

CVE-2005-2059

MEDIUM
6.50 CVSS 3.1

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2005-2033

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.

Path Traversal
WAF: High

CVE-2005-2022

MEDIUM
4.30 CVSS 2.0

Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1475

HIGH
7.50 CVSS 2.0

The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.

Open Redirect
WAF: Medium

CVE-2005-1669

MEDIUM
6.80 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1965

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.

Code Injection
WAF: Medium

CVE-2005-2035

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

SQL Injection
WAF: High

CVE-2005-1306

HIGH
7.50 CVSS 3.1

The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."

XML External Entity (XXE)
WAF: High

CVE-2005-1996

MEDIUM
5.00 CVSS 2.0

PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.

Code Injection
WAF: Medium

CVE-2005-0563

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("jav&#X41sc
ript:") in an IMG tag.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1957

HIGH
7.50 CVSS 2.0

mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.

Improper Authentication
WAF: Low

CVE-2005-1868

HIGH
7.50 CVSS 2.0

I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.

Unrestricted File Upload
WAF: Medium

CVE-2005-1876

MEDIUM
4.40 CVSS 2.0

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

Code Injection
WAF: Medium

CVE-2005-1894

HIGH
7.50 CVSS 2.0

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

Code Injection
WAF: Medium

CVE-2005-1947

MEDIUM
4.30 CVSS 3.1

Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2005-1881

HIGH
7.50 CVSS 2.0

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.

Unrestricted File Upload
WAF: Medium

CVE-2005-1813

HIGH
7.80 CVSS 2.0

Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences.

Path Traversal
WAF: High

CVE-2005-1778

LOW
2.60 CVSS 2.0

Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1787

HIGH
7.50 CVSS 2.0

setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.

Improper Input Validation
WAF: Medium

CVE-2005-1795

HIGH
7.50 CVSS 2.0

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.

Improper Input Validation
WAF: Medium

CVE-2005-1682

LOW
2.10 CVSS 2.0

JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users' e-mail messages by modifying the msgno parameter. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products.

Improper Input Validation
WAF: Medium
Page 3 of 4 (192 CVEs)