Latest CVE Feed
-
9.4
HIGHCVE-2005-4332
Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service or upload files via direct requests to obsolete JSP files including (1) admin/uploadclient.jsp, (2) apply_firmw... Read more
Affected Products : network_admission_control_manager_and_server_system_software- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4327
Multiple cross-site scripting (XSS) vulnerabilities in Michael Arndt WebCal 1.11-3.04 allow remote attackers to inject arbitrary web script or HTML via the (1) function, (2) year, and (3) date parameters to webcal.cgi, (4) new calendar entries, and (5) no... Read more
Affected Products : webcal- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4316
HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.... Read more
Affected Products : hp-ux- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4330
SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters.... Read more
Affected Products : ihtml_merchant_mall- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4331
SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters.... Read more
Affected Products : ihtml_merchant- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4335
ProjectForum 4.7.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted pageid parameter to admin/versions.html.... Read more
Affected Products : projectforum- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4317
Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote attackers to use the _SERVER[REMOTE_ADDR] parameter to (1) conduct cross-site scripting (XSS) attacks in the s... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4322
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attacker... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4326
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), which allows remote attackers to sniff authentication credentials.... Read more
Affected Products : powerchute_network_shutdown- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4318
SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4325
Multiple unspecified vulnerabilities in Driverse before 0.56b have unknown impact and attack vectors, related to (1) a "ptrace exploit" and (2) "some other potential security problems."... Read more
Affected Products : driverse- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4321
The Internet Key Exchange version 1 (IKEv1) implementation in Apani Networks EpiForce 1.9 and earlier running IPSec, allow remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for I... Read more
Affected Products : epiforce_agent- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4323
Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of ser... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4319
Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." sequences in the option parameter.... Read more
Affected Products : limbo_cms- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4313
SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : almond_personals- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4303
SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.... Read more
Affected Products : ezdatabase- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4308
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.... Read more
Affected Products : ezupload_pro- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4311
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4315
SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.... Read more
Affected Products : plexcart_x3- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4314
Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.... Read more
Affected Products : ppcal_shopping_cart- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025