Latest CVE Feed
-
7.5
HIGHCVE-2005-3043
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.... Read more
Affected Products : mall23- EPSS Score: %1.32
- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3039
SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.... Read more
Affected Products : mall23- EPSS Score: %0.58
- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3034
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.... Read more
Affected Products : driverstudio- EPSS Score: %0.56
- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3035
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.... Read more
Affected Products : driverstudio- EPSS Score: %0.92
- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3038
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."... Read more
Affected Products : hosting_controller- EPSS Score: %0.39
- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3023
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) e... Read more
Affected Products : vbulletin- EPSS Score: %0.35
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3029
Stack-based buffer overflow in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to execute arbitrary code via a long filname in an ACE archive.... Read more
- EPSS Score: %4.64
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3024
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) us... Read more
Affected Products : vbulletin- EPSS Score: %0.52
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3027
Sybari Antigen 8.0 SR2 does not properly filter SMTP messages, which allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment".... Read more
Affected Products : antigen- EPSS Score: %1.27
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3020
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) g... Read more
Affected Products : vbulletin- EPSS Score: %0.48
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3022
Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalenda... Read more
Affected Products : vbulletin- EPSS Score: %0.52
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3018
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.... Read more
Affected Products : safari- EPSS Score: %4.45
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3019
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools... Read more
Affected Products : vbulletin- EPSS Score: %0.65
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3021
image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.... Read more
Affected Products : vbulletin- EPSS Score: %0.20
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3026
Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.... Read more
Affected Products : epay- EPSS Score: %4.21
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3030
Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to write arbitrary files via a .. (do... Read more
- EPSS Score: %2.63
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3025
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.p... Read more
Affected Products : vbulletin- EPSS Score: %0.35
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3015
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.... Read more
- EPSS Score: %0.35
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3017
PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS).... Read more
Affected Products : content2web- EPSS Score: %0.35
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3014
Cross-site scripting (XSS) vulnerability in Ensim webplliance allows remote attackers to inject arbitrary web script or HTML via the Login (OCW_login_username) field.... Read more
Affected Products : webppliance- EPSS Score: %0.34
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025