Latest CVE Feed
-
7.5
HIGHCVE-2005-1894
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed b... Read more
Affected Products : flatnuke- EPSS Score: %7.81
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1905
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.... Read more
- EPSS Score: %0.15
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1871
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."... Read more
Affected Products : drupal- EPSS Score: %0.74
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1897
Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.... Read more
Affected Products : flexcast_audio_video_streaming_server- EPSS Score: %0.39
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1904
SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : jiro_upload_system- EPSS Score: %0.50
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1896
Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.... Read more
Affected Products : flatnuke- EPSS Score: %0.90
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1867
Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.... Read more
Affected Products : brightmail_antispam- EPSS Score: %1.13
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1964
PHP remote file inclusion vulnerability in utilit.php for Ovidentia Portal allows remote attackers to execute arbitrary PHP code via the babInstallPath parameter.... Read more
Affected Products : ovidentia- EPSS Score: %0.64
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1864
PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.... Read more
Affected Products : calendarix_advanced- EPSS Score: %0.38
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1895
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.... Read more
Affected Products : flatnuke- EPSS Score: %3.86
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1944
xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.... Read more
Affected Products : xmysqladmin- EPSS Score: %0.07
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1899
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP pack... Read more
Affected Products : raknet- EPSS Score: %4.59
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1870
PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to execute arbitrary PHP code via the form parameter.... Read more
Affected Products : popper- EPSS Score: %4.07
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-1902
Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, an... Read more
Affected Products : spa-pro_mail_atsolomon- EPSS Score: %3.10
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1898
The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.... Read more
Affected Products : phpthumb- EPSS Score: %0.39
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1893
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.... Read more
Affected Products : flatnuke- EPSS Score: %5.68
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1868
I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension.... Read more
Affected Products : i-man- EPSS Score: %1.40
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1874
Directory traversal vulnerability in Dzip before 2.9 allows remote attackers to create arbitrary files via a filename containing a .. (dot dot) in a .dz archive.... Read more
Affected Products : dzip- EPSS Score: %1.36
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1900
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.... Read more
Affected Products : sawmill- EPSS Score: %1.03
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1911
The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).... Read more
Affected Products : leafnode- EPSS Score: %0.48
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025