Latest CVE Feed
-
3.5
LOWCVE-2005-4190
Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) L... Read more
Affected Products : horde_application_framework- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4199
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcode... Read more
Affected Products : mybb- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4207
SQL injection vulnerability in BTGrup Admin WebController Script allows remote attackers to execute SQL commands via the (1) Username and (2) Password fields.... Read more
Affected Products : admin_webcontroller_script- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4193
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER['PHP_SELF'] variable.... Read more
Affected Products : usebb- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4201
Directory traversal vulnerability in My Album Online 1.0 allows remote attackers to access arbitrary files via ".../" (triple dot) sequences in unspecified vectors.... Read more
Affected Products : my_album_online- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2005-4191
Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description,... Read more
Affected Products : nag_task_list_manager_h3- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4209
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, poss... Read more
- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4196
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResour... Read more
Affected Products : scout_portal_toolkit- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4203
LogiSphere 0.9.9j does not restrict the number of messages that can be sent, which allows remote attackers to cause a denial of service by sending a large number of messages via the msg command. NOTE: due to lack of appropriate details by the original re... Read more
Affected Products : logisphere- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4204
Cross-site scripting (XSS) vulnerability in LogiSphere 0.9.9j allows remote attackers to inject arbitrary Javascript via the msg command. NOTE: due to lack of appropriate details by the original researcher, it is unclear whether this issue is distinct fro... Read more
Affected Products : logisphere- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4194
Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cause a denial of service (application crash) via a long query string.... Read more
Affected Products : sights_n_sounds_streaming_media_server- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4195
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the ParentId parameter in SPT--BrowseResources.php, (2) ResourceId parameter in SPT--FullRecord.php, (3... Read more
- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4202
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) "..." (triple dot), and (3) "..//" sequences in the URL, (4) "../" sequences in the source parameter to viewsource... Read more
Affected Products : logisphere- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4210
Opera before 8.51, when running on Windows with Input Method Editor (IME) installed, allows remote attackers to cause a denial of service (persistent application crash) by bookmarking a site with a long title.... Read more
Affected Products : opera_browser- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2005-4192
Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when ... Read more
Affected Products : mnemo_note_manager_h3- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
6.1
MEDIUMCVE-2005-4206
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loa... Read more
Affected Products : academic_suite- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4197
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a parameter, which is executed with extra privileges in a cryptographically signed Java Applet.... Read more
Affected Products : ssl_vpn- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2005-4189
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith H3 before 2.0.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Calendar name field when creating calendars, (2) event title field when deleting eve... Read more
Affected Products : kronolith_h3- Published: Dec. 13, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-4178
Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operations.... Read more
- Published: Dec. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4177
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter.... Read more
- Published: Dec. 12, 2005
- Modified: Apr. 03, 2025