Latest CVE Feed
-
5.0
MEDIUMCVE-2005-4214
phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4218
SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands via the msg parameter, a different vulnerability than CVE-2005-3585.... Read more
Affected Products : phpwebthings- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4234
SQL injection vulnerability in gallery.php in EncapsGallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : encapsgallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4246
SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter.... Read more
Affected Products : plogger- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4238
Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.... Read more
Affected Products : mantis- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2831
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use ... Read more
- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3903
Buffer overflow in uidadmin in SCO Unixware 7.1.3 and 7.1.4 allows local users to execute arbitrary code via a -S (scheme) argument that specifies a large file, a different vulnerability than CVE-2001-1063.... Read more
Affected Products : unixware- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4232
SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and di... Read more
Affected Products : jamit_job_board- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4217
Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.... Read more
Affected Products : mac_os_x_server- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4237
Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.... Read more
Affected Products : mysqlauction- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4221
SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).... Read more
Affected Products : arab_portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4226
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters... Read more
Affected Products : phpwebthings- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4227
Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_m... Read more
Affected Products : dcp-portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4225
Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameter... Read more
Affected Products : mybloggie- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4215
Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).... Read more
Affected Products : motorola_cable_modem- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4252
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4240
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.... Read more
Affected Products : vcd-db- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4219
setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it wou... Read more
Affected Products : innovative_cms- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4241
Cross-site scripting (XSS) vulnerability in the category page in VCD-db 0.98 and earlier allows remote attackers to inject arbitrary web script or HTML via the batch parameter.... Read more
Affected Products : vcd-db- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4250
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025