Latest CVE Feed
-
7.5
HIGHCVE-2005-2113
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger... Read more
Affected Products : xoops- EPSS Score: %0.97
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1931
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.... Read more
Affected Products : goodtech_smtp_server- EPSS Score: %4.01
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2110
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an erro... Read more
Affected Products : wordpress- EPSS Score: %1.23
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2112
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.... Read more
Affected Products : xoops- EPSS Score: %0.56
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2089
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes II... Read more
Affected Products : internet_information_services- EPSS Score: %31.00
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1917
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.... Read more
Affected Products : kpopper- EPSS Score: %0.08
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2136
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrar... Read more
- EPSS Score: %0.15
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2138
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.... Read more
Affected Products : comdev_ecommerce- EPSS Score: %0.33
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2091
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which... Read more
Affected Products : websphere_application_server- EPSS Score: %1.65
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2092
BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes... Read more
Affected Products : weblogic_server- EPSS Score: %2.11
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2069
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sni... Read more
- EPSS Score: %2.84
- Published: Jun. 30, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-2059
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via ... Read more
Affected Products : ubb.threads- EPSS Score: %0.32
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2061
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.... Read more
Affected Products : ubb.threads- EPSS Score: %0.38
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2066
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.... Read more
Affected Products : asp-nuke- EPSS Score: %1.46
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2065
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.... Read more
Affected Products : asp-nuke- EPSS Score: %4.11
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0201
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.... Read more
- EPSS Score: %0.07
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2076
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.... Read more
Affected Products : version_control_repository_manager- EPSS Score: %0.19
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-2057
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to new... Read more
Affected Products : ubb.threads- EPSS Score: %1.17
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2063
Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.... Read more
Affected Products : activebuyandsell- EPSS Score: %0.30
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2078
BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.... Read more
Affected Products : bisonftp- EPSS Score: %0.61
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025