Latest CVE Feed
-
7.5
HIGHCVE-2005-3572
SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.... Read more
Affected Products : peel- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3546
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3558
PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters.... Read more
Affected Products : oste- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3586
content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error.... Read more
Affected Products : mambo- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-3548
Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field.... Read more
Affected Products : invision_board- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-3567
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.... Read more
Affected Products : tivoli_directory_server- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3570
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".... Read more
Affected Products : horde- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3592
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.... Read more
Affected Products : cutenews- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3579
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.... Read more
Affected Products : walla_telesite- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3560
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filt... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3582
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.... Read more
Affected Products : imagemagick- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3554
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.... Read more
Affected Products : phpkit- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3569
INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.... Read more
Affected Products : db2_content_manager- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3547
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Pass... Read more
Affected Products : invision_board- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3594
game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables.... Read more
Affected Products : e107- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3584
Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter.... Read more
Affected Products : phpwebthings- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3575
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : cyphor- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3545
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.... Read more
Affected Products : ibproarcade- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-3549
Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".... Read more
Affected Products : invision_board- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3556
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) t... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025