Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4322
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attacker... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4326
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartext (base64-encoded), which allows remote attackers to sniff authentication credentials.... Read more
Affected Products : powerchute_network_shutdown- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4323
Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of ser... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4334
SQL injection vulnerability in ZixForum 1.12 allows remote attackers to execute arbitrary SQL commands via the H_ID parameter to (1) zixforum/forum.asp, as used in (2) Headforums.asp and (3) Subject.asp.... Read more
Affected Products : zixforum- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4302
Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter.... Read more
Affected Products : ezdatabase- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4309
SQL injection vulnerability in ezUpload Pro 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.... Read more
Affected Products : ezupload_pro- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4308
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.... Read more
Affected Products : ezupload_pro- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4303
SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter.... Read more
Affected Products : ezdatabase- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4311
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.... Read more
- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4306
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.... Read more
Affected Products : sitenet_bbs- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4315
SQL injection vulnerability in the search function in Plexum PLEXCART X3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly involving the (1) s_itemname and (2) s_orderby parameters to plexcart.pl.... Read more
Affected Products : plexcart_x3- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4312
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : almond_classifieds- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4314
Cross-site scripting (XSS) vulnerability in ppcal.cgi in PPCal Shopping Cart 3.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) stop and (2) user parameters.... Read more
Affected Products : ppcal_shopping_cart- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4307
Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.... Read more
Affected Products : scarecrow- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4313
SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : almond_personals- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4304
index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has termin... Read more
Affected Products : ezdatabase- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4305
Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.... Read more
Affected Products : trac- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4310
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.... Read more
Affected Products : tectia_server- Published: Dec. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4297
Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly via the "keys" parameter.... Read more
Affected Products : bbboard- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3652
Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.... Read more
Affected Products : ica_program_neighborhood_client- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025