Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4354
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : webglimpse- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4353
SQL injection vulnerability in index.php in toendaCMS 0.6.2.1, when configured to use a SQL database, allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : toendacms- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4350
Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 and A.02.x before A.02.00.08 on HP-UX B.11.00 through B.11.23 allows remote attackers to cause an unspecified denial of service via unknown attack vectors.... Read more
Affected Products : wbem_services- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-4349
SQL injection vulnerability in server_privileges.php in phpMyAdmin 2.7.0 allows remote authenticated users to execute arbitrary SQL commands via the (1) dbname and (2) checkprivs parameters. NOTE: the vendor and a third party have disputed this issue, sa... Read more
Affected Products : phpmyadmin- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4346
Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a ... Read more
Affected Products : phpbb_blog- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-4345
Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges.... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4337
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4344
Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration.... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4343
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, ak... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4341
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether th... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4339
Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to anno... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4338
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to "admin".... Read more
Affected Products : academic_suite- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4342
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox ... Read more
Affected Products : coldfusion- Published: Dec. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4333
Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, and (3) board parameters to reply.pl, (4) branch, (5) boar... Read more
Affected Products : binary_board_system- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4335
ProjectForum 4.7.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted pageid parameter to admin/versions.html.... Read more
Affected Products : projectforum- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4330
SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters.... Read more
Affected Products : ihtml_merchant_mall- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4331
SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.... Read more
Affected Products : ihtml_merchant- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
9.4
HIGHCVE-2005-4332
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmw... Read more
Affected Products : network_admission_control_manager_and_server_system_software- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4324
Hitachi Groupmax Mail SMTP 06-50 through 06-52-/A and 07-00 through 07-20 allows remote attackers to cause a denial of service (service stop) via an e-mail message with an "invalid format."... Read more
Affected Products : groupmax_mail_smtp- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4317
Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the s... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025