Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3894
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the Queu... Read more
Affected Products : otrs- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3890
Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs.... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-3895
Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which al... Read more
Affected Products : otrs- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3896
Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function.... Read more
Affected Products : mozilla- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2005-2124
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafte... Read more
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3886
Unspecified vulnerability in Cisco Security Agent (CSA) 4.5.0 and 4.5.1 agents, when running on Windows systems, allows local users to bypass protections and gain system privileges by executing certain local software.... Read more
Affected Products : security_agent- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3885
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.... Read more
Affected Products : inkscape- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3879
Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbres_id parameter in (a) details_res.php, (b) refer_friend.php, and (c) report_link.php, and... Read more
Affected Products : resource_repository_script- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3874
SQL injection vulnerability in netzbr.php in Netzbrett 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the p_entry parameter in an entry command to index.php.... Read more
Affected Products : netzbrett- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3876
Multiple SQL injection vulnerabilities in adcbrowres.php in AD Center ADC2000 NG Pro 1.2 and NG Pro Lite allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) lang parameters.... Read more
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3881
SQL injection vulnerability in search.php in AtlantisFAQ Knowledge Base Software 2.03 and earlier allows remote attackers to execute arbitrary SQL commands via the searchStr parameter.... Read more
Affected Products : altantis_knowledge_base_software- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3870
Multiple SQL injection vulnerabilities in edmobbs9r.php in edmoBBS 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) table and (2) messageID parameters.... Read more
Affected Products : edmobbs- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3884
Multiple SQL injection vulnerabilities in the search action in Zainu 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term and (2) start parameters to index.php.... Read more
Affected Products : zainu- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3859
PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.... Read more
Affected Products : q-news- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3860
PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.... Read more
Affected Products : athena_php_website_administration- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3882
SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : faqring_knowledge_base_software- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3862
Buffer overflow in unalz before 0.53 allows remote attackers to execute arbitrary code via long file names in ALZ archives.... Read more
Affected Products : unalz- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3883
CRLF injection vulnerability in the mb_send_mail function in PHP before 5.1.0 might allow remote attackers to inject arbitrary e-mail headers via line feeds (LF) in the "To" address argument.... Read more
Affected Products : php- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3861
PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.... Read more
Affected Products : phpgreetz- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3875
Multiple SQL injection vulnerabilities in Enterprise Connector 1.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the messageid parameter in (1) send.php or (2) a delete action in messages.php.... Read more
Affected Products : enterprise_connector- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025