2005 CVE Vulnerabilities

4,770 CVEs published in 2005.

CVE IDSeverityCVSSDescription
CVE-2005-4044Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attack...
CVE-2005-4013PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote ...
CVE-2005-4009Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute ar...
CVE-2005-4010SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands...
CVE-2005-4011SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier ...
CVE-2005-4012Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary...
CVE-2005-4014stat.php in PHP Web Statistik 1.4 allows remote attackers to cause a denial of service (CPU consumption) via a large las...
CVE-2005-4015PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attac...
CVE-2005-4016SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the ...
CVE-2005-4017property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value,...
CVE-2005-4018SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers ...
CVE-2005-4019SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to exe...
CVE-2005-4020SQL injection vulnerability in create.php in Widget Imprint 1.0.26 and earlier allows remote attackers to execute arbitr...
CVE-2005-4021The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access c...
CVE-2005-4022Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote a...
CVE-2005-4023Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary fi...
CVE-2005-4024Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrar...
CVE-2005-4025Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows rem...
CVE-2005-4027SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified s...
CVE-2005-4029WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, w...
CVE-2005-4028Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or ...
CVE-2005-4008SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL co...
CVE-2005-4026search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive inf...
CVE-2005-4005SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information an...
CVE-2005-4006SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (...

Check if your code is affected by 2005 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now