Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3422
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : asp_fast_forum- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3419
SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3420
usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3417
phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables.... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3421
estcmd in Hyper Estraier 1.0.1 on Windows systems allows remote attackers to read unauthorized files via a crafted search request for a filename that contains Unicode characters.... Read more
Affected Products : hyper_estraier- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3416
phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote attackers to bypass security checks by setting the $_SESSION and $HTTP_SESSION_VARS variables to strings inste... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3415
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] varia... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3418
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) list_cat... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3413
Cross-site scripting (XSS) vulnerability in desktop.php in eyeOS 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the motd parameter.... Read more
Affected Products : eyeos- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3414
eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials.... Read more
Affected Products : eyeos- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3411
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.... Read more
Affected Products : snitz_forums_2000- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3412
Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag.... Read more
Affected Products : elite_forum- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3400
Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe... Read more
Affected Products : fortinet- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3402
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection vi... Read more
Affected Products : thunderbird- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3390
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request wi... Read more
Affected Products : php- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2752
An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.... Read more
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2749
Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder to misrepresent file and group ownership information. NOTE: it is not clear whether this issue satisfies the CVE definition of a vulnerability.... Read more
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3387
The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.... Read more
Affected Products : ntop- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3313
The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop).... Read more
Affected Products : ethereal- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3388
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."... Read more
Affected Products : php- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025