Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2734
Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : gallery- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2718
Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.... Read more
Affected Products : mplayer- Published: Aug. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2717
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.... Read more
Affected Products : webcalendar- Published: Aug. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2716
The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.... Read more
Affected Products : affix- Published: Aug. 29, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2693
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.... Read more
Affected Products : cvs- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2698
Cross-site scripting (XSS) vulnerability in browse.php in Nephp Publisher Enterprise 3.04 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded keywords parameter.... Read more
Affected Products : nephp_publisher_enterprise- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2696
IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "P... Read more
Affected Products : lotus_notes- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2695
Unspecified vulnerability in the SSL certificate checking functionality in Cisco CiscoWorks Management Center for IDS Sensors (IDSMC) 2.0 and 2.1, and Monitoring Center for Security (Security Monitor or Secmon) 1.1 through 2.0 and 2.1, allows remote attac... Read more
- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2697
SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282.... Read more
Affected Products : mybulletinboard- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2699
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator... Read more
Affected Products : phpkit- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2694
Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that contains an entry with a long file name.... Read more
Affected Products : winace- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2686
Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.ph... Read more
Affected Products : savewebportal- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2691
includes/common.php in RunCMS 1.2 and earlier calls the extract function with EXTR_OVERWRITE on HTTP POST variables, which allows remote attackers to overwrite arbitrary variables, possibly allowing execution of arbitrary code.... Read more
Affected Products : runcms- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2687
PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php.... Read more
Affected Products : savewebportal- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2685
SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via a direct request to admin/PhpMyExplorer/editerfichier.php, then editing the desired file to contain the PHP code, as demonstrated using header.php in the fichier parameter. NOTE:... Read more
Affected Products : savewebportal- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2688
Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal 3.4 allow remote attackers to inject arbitrary web script or HTML via a large number of parameters to (1) footer.php, (2) header.php, (3) menu_dx.php, or (4) menu_sx.php, or Javascript c... Read more
Affected Products : savewebportal- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2690
SQL injection vulnerability in the Downloads module in PostNuke 0.760-RC4b allows PostNuke administrators to execute arbitrary SQL commands via the show parameter to dl-viewdownload.php.... Read more
Affected Products : postnuke- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2692
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2) subquery parameters to the newbb plus module, the forum parameter to (3) newtopic.php, (4) edit.php, or ... Read more
Affected Products : runcms- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2689
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.... Read more
Affected Products : postnuke- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2531
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which a... Read more
Affected Products : openvpn- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025