CVE Database - 2005

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

192
Matching CVEs
15853
Critical
26962
High
69389
High WAF Coverage

CVE-2005-1260

MEDIUM
5.00 CVSS 2.0

bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").

Uncontrolled Resource Consumption
WAF: Medium

CVE-2005-1674

MEDIUM
6.50 CVSS 3.1

Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2005-1628

HIGH
7.50 CVSS 2.0

apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.

Improper Input Validation
WAF: Medium

CVE-2005-1619

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1486

MEDIUM
5.00 CVSS 2.0

Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but believes that they have been addressed. The original researcher is known to be unreliable.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1487

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be unreliable

SQL Injection
WAF: High

CVE-2005-1500

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no parameter in viewdate mode, (3) the cat_id parameter in viewcat mode, the (4) month_no or (5) year parameter in viewmonth mode, or (6) post_id parameter in viewid mode to index.php. NOTE: item (1) was discovered to affect 2.1.3 as well.

SQL Injection
WAF: High

CVE-2005-1330

MEDIUM
4.90 CVSS 2.0

AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.

Improper Input Validation
WAF: Medium

CVE-2005-1398

MEDIUM
5.00 CVSS 2.0

phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.

Improper Input Validation
WAF: Medium

CVE-2005-0050

HIGH
10.00 CVSS 2.0

The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, aka the "License Logging Service Vulnerability."

Improper Input Validation
WAF: Medium

CVE-2005-0200

HIGH
7.50 CVSS 2.0

TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.

Improper Input Validation
WAF: Medium

CVE-2005-0209

HIGH
7.80 CVSS 2.0

Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.

Improper Input Validation
WAF: Medium

CVE-2005-0227

MEDIUM
4.30 CVSS 2.0

PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.

Code Injection
WAF: Medium

CVE-2005-0251

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the search parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-0252

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password.

SQL Injection
WAF: High

CVE-2005-0253

MEDIUM
4.00 CVSS 2.0

Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete arbitrary files via a Delete action and .. (dot dot) sequences in the database_name parameter.

Path Traversal
WAF: High

CVE-2005-0254

MEDIUM
4.30 CVSS 2.0

BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.

Unrestricted File Upload
WAF: Medium

CVE-2005-0372

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.

Path Traversal
WAF: High

CVE-2005-0449

HIGH
7.10 CVSS 2.0

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

Improper Input Validation
WAF: Medium

CVE-2005-0492

LOW
2.60 CVSS 2.0

Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.

Improper Input Validation
WAF: Medium

CVE-2005-0679

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code. NOTE: it was later reported that 2.4 is also affected.

Code Injection
WAF: Medium

CVE-2005-0709

MEDIUM
4.60 CVSS 2.0

MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit.

Code Injection
WAF: Medium

CVE-2005-0738

MEDIUM
5.00 CVSS 2.0

Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2005-0850

MEDIUM
5.00 CVSS 2.0

FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

Improper Input Validation
WAF: Medium

CVE-2005-0896

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-0904

LOW
2.10 CVSS 2.0

Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.

Improper Input Validation
WAF: Medium

CVE-2005-1006

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-1017

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp.

SQL Injection
WAF: High

CVE-2005-1020

HIGH
7.10 CVSS 2.0

Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and an SSH session is terminated while the server is sending data.

Improper Authentication
WAF: Low

CVE-2005-1155

HIGH
7.50 CVSS 2.0

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."

Code Injection
WAF: Medium

CVE-2005-0413

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

SQL Injection
WAF: High

CVE-2005-0420

MEDIUM
5.80 CVSS 2.0

Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

Open Redirect
WAF: Medium

CVE-2005-0477

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-0485

MEDIUM
6.80 CVSS 2.0

Cross-site scripting (XSS) vulnerability in comment.php for paNews 2.0b4 for PHP Arena allows remote attackers to inject arbitrary HTML and web script via the showpost parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-0748

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.

Code Injection
WAF: Medium

CVE-2005-0720

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.

Code Injection
WAF: Medium

CVE-2005-0543

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2005-0103

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.

Code Injection
WAF: Medium

CVE-2005-0116

HIGH
7.50 CVSS 2.0

AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

Improper Input Validation
WAF: Medium

CVE-2004-1019

HIGH
10.00 CVSS 2.0

The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.

Improper Input Validation
WAF: Medium

CVE-2004-1125

HIGH
9.30 CVSS 2.0

Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.

Improper Input Validation
WAF: Medium

CVE-2004-1201

MEDIUM
5.00 CVSS 2.0

Opera 7.54 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

Uncontrolled Resource Consumption
WAF: Medium
Page 4 of 4 (192 CVEs)