Latest CVE Feed
-
5.0
MEDIUMCVE-2005-4346
Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a ... Read more
Affected Products : phpbb_blog- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4343
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, ak... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4337
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4338
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to "admin".... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4339
Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to anno... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4342
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox ... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4341
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether th... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4344
Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration.... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4322
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attacker... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4326
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), which allows remote attackers to sniff authentication credentials.... Read more
Affected Products : powerchute_network_shutdown- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4325
Multiple unspecified vulnerabilities in Driverse before 0.56b have unknown impact and attack vectors, related to (1) a "ptrace exploit" and (2) "some other potential security problems."... Read more
Affected Products : driverse- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4323
Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of ser... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4334
SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.asp.... Read more
Affected Products : zixforum- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4321
The Internet Key Exchange version 1 (IKEv1) implementation in Apani Networks EpiForce 1.9 and earlier running IPSec, allow remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for I... Read more
Affected Products : epiforce_agent- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4319
Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." sequences in the option parameter.... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4320
Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2) element.inc.php, and (3) node.inc.php, which leaks the path in an error message.... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4328
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.... Read more
Affected Products : webglimpse- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4329
SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter.... Read more
Affected Products : pafiledb- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4318
SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4327
Multiple cross-site scripting (XSS) vulnerabilities in Michael Arndt WebCal 1.11-3.04 allow remote attackers to inject arbitrary web script or HTML via the (1) function, (2) year, and (3) date parameters to webcal.cgi, (4) new calendar entries, and (5) no... Read more
Affected Products : webcal- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025