Latest CVE Feed
-
7.5
HIGHCVE-2005-1558
The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.... Read more
Affected Products : nexusway- EPSS Score: %0.59
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2005-1488
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.ht... Read more
- EPSS Score: %0.05
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1486
Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendo... Read more
Affected Products : fishcart- EPSS Score: %8.74
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1517
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).... Read more
Affected Products : firewall_services_module- EPSS Score: %0.39
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1588
SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and ther... Read more
Affected Products : quick.cart- EPSS Score: %0.45
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1498
Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which ... Read more
Affected Products : mybloggie- EPSS Score: %4.97
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1510
PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in an error message.... Read more
Affected Products : pwsphp- EPSS Score: %0.72
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1495
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.... Read more
- EPSS Score: %1.04
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1512
The Admin panel in PwsPHP 1.2.2 does not properly verify uploaded picture files, which allows remote attackers to upload and possibly execute arbitrary files.... Read more
Affected Products : pwsphp- EPSS Score: %0.74
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1497
index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.... Read more
Affected Products : mybloggie- EPSS Score: %0.39
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1485
Golden FTP Server Pro 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.... Read more
Affected Products : golden_ftp_server- EPSS Score: %0.39
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1494
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.... Read more
Affected Products : megabook- EPSS Score: %0.42
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1504
GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.... Read more
Affected Products : cd-key_validation_system- EPSS Score: %1.03
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1501
MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message.... Read more
Affected Products : midicart_php_shopping_cart- EPSS Score: %0.74
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1557
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.... Read more
Affected Products : guestbook_pro- EPSS Score: %0.68
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0039
Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in... Read more
Affected Products : ipsec- EPSS Score: %2.29
- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1555
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.... Read more
Affected Products : coldfusion- EPSS Score: %0.20
- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1476
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.... Read more
Affected Products : firefox- EPSS Score: %49.76
- Published: May. 09, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1477
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combi... Read more
Affected Products : firefox- EPSS Score: %41.65
- Published: May. 09, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1399
FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.... Read more
Affected Products : freebsd- EPSS Score: %0.05
- Published: May. 06, 2005
- Modified: Apr. 03, 2025