Latest CVE Feed
-
7.5
HIGHCVE-2005-4303
SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.... Read more
Affected Products : ezdatabase- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4315
SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.... Read more
Affected Products : plexcart_x3- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4311
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4308
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.... Read more
Affected Products : ezupload_pro- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4312
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : almond_classifieds- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4304
index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has termin... Read more
Affected Products : ezdatabase- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4310
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.... Read more
Affected Products : tectia_server- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4307
Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.... Read more
Affected Products : scarecrow- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4300
Format string vulnerability in the lire_pop function in pop.c in libremail 1.1.0 and earlier, with compiled with the debug option, allows remote attackers to execute arbitrary code via a crafted e-mail or POP server response.... Read more
Affected Products : libremail- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4297
Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly via the "keys" parameter.... Read more
Affected Products : bbboard- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4301
Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.... Read more
Affected Products : phpxplorer- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4298
Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters.... Read more
Affected Products : atlantforum- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3652
Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.... Read more
Affected Products : ica_program_neighborhood_client- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4299
Cross-site scripting (XSS) vulnerability in atl.cgi in Atlant Pro 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) before and (2) ct parameters.... Read more
Affected Products : atlant_pro- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4275
Scientific Atlanta DPX2100 Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD), as demonstrated using hping2. NOTE: the ... Read more
Affected Products : dpx2100_cable_modem- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4296
AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.... Read more
Affected Products : appserv- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4290
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.... Read more
Affected Products : ecw-cart- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-4278
Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.... Read more
Affected Products : perl- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4283
Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cgi.... Read more
Affected Products : the_city_shop- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4295
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from thi... Read more
Affected Products : absolute_image_gallery_xe- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025