Latest CVE Feed
-
6.5
MEDIUMCVE-2005-4424
Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename endi... Read more
Affected Products : phpkit- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4404
SQL injection vulnerability in default.asp in Media2 CMS Shop 18.x allows remote attackers to execute arbitrary SQL commands via the item parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.... Read more
Affected Products : media2_cms_shop- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4394
Cross-site scripting (XSS) vulnerability in EPiX 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search query parameters.... Read more
Affected Products : epix- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4406
SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.... Read more
Affected Products : mercury_cms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4419
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.... Read more
- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4407
Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters.... Read more
Affected Products : mercury_cms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4397
SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter.... Read more
Affected Products : icms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4414
Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."... Read more
Affected Products : teamwork- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-4422
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/image... Read more
Affected Products : toendacms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4380
Multiple SQL injection vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) users/my.php; the (2) ... Read more
Affected Products : bitweaver- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4378
SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.... Read more
Affected Products : baseline_cms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4375
Cross-site scripting (XSS) vulnerability in Amaxus 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the change parameter. NOTE: it is possible that this is resultant from CVE-2005-4376.... Read more
Affected Products : amaxus- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4388
Cross-site scripting (XSS) vulnerability in search.cfm in CONTENS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the near parameter.... Read more
Affected Products : contens- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4376
Directory traversal vulnerability in Amaxus 3 and earlier allows remote attackers to access arbitrary files via ".." sequences in the change parameter.... Read more
Affected Products : amaxus- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4385
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.... Read more
Affected Products : cofax- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4389
search.cfm in CONTENS 3.0 and earlier allows remote attackers to obtain the full server path via invalid (1) submit.y, (2) bool, (3) itemsperpage, (4) submit, (5) submit.x, (6) criteria, (7) advanced, and (8) intern parameters.... Read more
Affected Products : contens- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4371
Acidcat 2.1.13 and earlier stores the database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a request to databases/acidcat.mdb.... Read more
Affected Products : acidcat- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4379
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.1 and 1.1.1 beta allow remote attackers to inject arbitrary web script or HTML via the (1) sort_mode parameter to (a) fisheye/list_galleries.php, (b) messages/message_box.php, and (c) user... Read more
Affected Products : bitweaver- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4377
Cross-site scripting (XSS) vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) PageID and (2) SiteNodeID parameters.... Read more
Affected Products : baseline_cms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4387
Cross-site scripting (XSS) vulnerability in home.php in contenite 0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : contenite- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025