Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4231
Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) link parameter to tell_friend.php, (2) phrase[] parameter to search.php in a search_links_advanced action, and ... Read more
Affected Products : link_up_gold- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4245
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.... Read more
Affected Products : snipe_gallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4224
Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hideemail, image, realname, signature, timezone, and xupexist parameters in signup.php, (2) the content_commen... Read more
Affected Products : e107- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4216
The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application crash) via a malformed request with a single character to port 1111.... Read more
Affected Products : flash_media_server- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4212
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4213
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4215
Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).... Read more
Affected Products : motorola_cable_modem- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2831
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use ... Read more
- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4221
SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).... Read more
Affected Products : arab_portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4226
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters... Read more
Affected Products : phpwebthings- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4227
Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_m... Read more
Affected Products : dcp-portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4225
Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameter... Read more
Affected Products : mybloggie- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4252
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4240
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.... Read more
Affected Products : vcd-db- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4219
setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it wou... Read more
Affected Products : innovative_cms- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4241
Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.... Read more
Affected Products : vcd-db- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4250
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4223
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster... Read more
Affected Products : utopia_news_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4229
Cross-site scripting (XSS) vulnerability in auction.pl in EveryAuction 1.53 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. NOTE: the provenance of this issue is unknown; the details were obtaine... Read more
Affected Products : everyauction- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4244
SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php.... Read more
Affected Products : snipe_gallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025