Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1769
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.... Read more
- EPSS Score: %1.64
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1949
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.... Read more
Affected Products : e107- EPSS Score: %1.01
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2036
modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.... Read more
Affected Products : cool_cafe_chat- EPSS Score: %0.86
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1963
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.... Read more
Affected Products : cerberus_helpdesk- EPSS Score: %0.59
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1975
Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters... Read more
Affected Products : 1two- EPSS Score: %0.53
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1269
Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.... Read more
- EPSS Score: %2.51
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1967
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCar... Read more
Affected Products : productcart_ecommerce- EPSS Score: %0.33
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1669
Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions ... Read more
Affected Products : opera_browser- EPSS Score: %0.44
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1965
PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.... Read more
Affected Products : siteframe- EPSS Score: %4.42
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2027
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.... Read more
Affected Products : vertical_horizon-2402s- EPSS Score: %0.30
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2035
SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : cool_cafe_chat- EPSS Score: %0.64
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2042
Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.... Read more
Affected Products : ajax-spell- EPSS Score: %0.38
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1720
AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permissions for that ACL.... Read more
Affected Products : afp_server- EPSS Score: %0.05
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1721
Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.... Read more
Affected Products : afp_server- EPSS Score: %0.88
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1722
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.... Read more
- EPSS Score: %0.05
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1951
Multiple HTTP Response Splitting vulnerabilities in osCommerce 2.2 Milestone 2 and earlier allow remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the (1) products_id or (2) pid parameter to index.php... Read more
Affected Products : oscommerce- EPSS Score: %4.25
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2030
Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat.... Read more
Affected Products : ultimate_php_board- EPSS Score: %1.54
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2005
Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.... Read more
Affected Products : ultimate_php_board- EPSS Score: %0.31
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1970
Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.... Read more
Affected Products : pcanywhere- EPSS Score: %0.07
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2026
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.... Read more
Affected Products : vertical_horizon-2402s- EPSS Score: %0.55
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025