Latest CVE Feed
-
7.5
HIGHCVE-2005-1957
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary f... Read more
Affected Products : file_upload_manager- EPSS Score: %0.84
- Published: Jun. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1959
jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.... Read more
Affected Products : jammail- EPSS Score: %4.38
- Published: Jun. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1956
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.... Read more
Affected Products : file_upload_manager- EPSS Score: %0.22
- Published: Jun. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1729
Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.... Read more
Affected Products : edirectory- EPSS Score: %2.53
- Published: Jun. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1953
Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.... Read more
Affected Products : pico_server- EPSS Score: %3.42
- Published: Jun. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1942
Cisco switches that support 802.1x security allow remote attackers to bypass port security and gain access to the VLAN via spoofed Cisco Discovery Protocol (CDP) messages.... Read more
Affected Products : catalyst- EPSS Score: %0.45
- Published: Jun. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1267
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.... Read more
- EPSS Score: %11.27
- Published: Jun. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1966
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.... Read more
Affected Products : e107- EPSS Score: %0.90
- Published: Jun. 10, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1901
Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User window or (2) the license key in the Licensing page.... Read more
Affected Products : sawmill- EPSS Score: %0.53
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1865
Multiple SQL injection vulnerabilities in Calendarix Advanced 1.5 allow remote attackers to execute arbitrary SQL commands via the catview parameter to (1) cal_week.php, (2) cal_cat.php, or (3) cal_day.php, or (4) id parameter to cal_pophols.php.... Read more
Affected Products : calendarix_advanced- EPSS Score: %2.04
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2005-1879
LutelWall 0.97 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.... Read more
Affected Products : lutelwall- EPSS Score: %0.04
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1884
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.... Read more
Affected Products : yapig- EPSS Score: %4.00
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1908
Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.... Read more
Affected Products : liteweb- EPSS Score: %0.52
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.5
MEDIUMCVE-2005-1876
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.... Read more
Affected Products : cutenews- EPSS Score: %0.74
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1892
FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root ... Read more
Affected Products : flatnuke- EPSS Score: %1.03
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1894
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed b... Read more
Affected Products : flatnuke- EPSS Score: %7.81
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1947
Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.... Read more
Affected Products : gallery- EPSS Score: %0.97
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1900
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.... Read more
Affected Products : sawmill- EPSS Score: %1.03
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1911
The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).... Read more
Affected Products : leafnode- EPSS Score: %0.48
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1763
Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.... Read more
- EPSS Score: %0.04
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025