Latest CVE Feed
-
7.5
HIGHCVE-2005-4221
SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).... Read more
Affected Products : arab_portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4237
Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.... Read more
Affected Products : mysqlauction- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4217
Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.... Read more
Affected Products : mac_os_x_server- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4232
SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and di... Read more
Affected Products : jamit_job_board- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4238
Cross-site scripting (XSS) vulnerability in view_filters_page.php in Mantis 1.0.0rc3 and earlier allows remote attackers to inject arbitrary web script or HTML via the target_field parameter.... Read more
Affected Products : mantis- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3903
Buffer overflow in uidadmin in SCO Unixware 7.1.3 and 7.1.4 allows local users to execute arbitrary code via a -S (scheme) argument that specifies a large file, a different vulnerability than CVE-2001-1063.... Read more
Affected Products : unixware- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2831
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use ... Read more
- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4222
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.... Read more
Affected Products : guestserver- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4251
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4216
The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application crash) via a malformed request with a single character to port 1111.... Read more
Affected Products : flash_media_server- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4213
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4212
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2829
Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display ... Read more
- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2830
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."... Read more
- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4224
Multiple "potential" SQL injection vulnerabilities in e107 0.7 might allow remote attackers to execute arbitrary SQL commands via (1) the email, hideemail, image, realname, signature, timezone, and xupexist parameters in signup.php, (2) the content_commen... Read more
Affected Products : e107- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4245
Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.... Read more
Affected Products : snipe_gallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4231
Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) link parameter to tell_friend.php, (2) phrase[] parameter to search.php in a search_links_advanced action, and ... Read more
Affected Products : link_up_gold- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4228
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, a... Read more
Affected Products : phpwebgallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4230
SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.... Read more
Affected Products : link_up_gold- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4211
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025