Latest CVE Feed
-
7.5
HIGHCVE-2005-2158
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.... Read more
Affected Products : jbpm- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2149
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.... Read more
Affected Products : cacti- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2160
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.... Read more
Affected Products : imail- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2166
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.... Read more
Affected Products : plague_news_system- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2161
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.... Read more
Affected Products : phpbb- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2152
SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.... Read more
Affected Products : geeklog- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2168
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.... Read more
Affected Products : plague_news_system- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2162
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.... Read more
Affected Products : myguestbook- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2154
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.... Read more
Affected Products : osticket_sts- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2165
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.... Read more
Affected Products : globalnotescript- Published: Jul. 06, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1917
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.... Read more
Affected Products : kpopper- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0360
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.... Read more
Affected Products : log_sink_class_activex_control- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2146
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.... Read more
Affected Products : tectia_server- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2107
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.... Read more
Affected Products : wordpress- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2109
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.... Read more
Affected Products : wordpress- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2144
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.... Read more
Affected Products : prevx_pro_2005- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2084
Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : community_server_forums- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1932
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arb... Read more
Affected Products : lpanel- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2019
ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does not sufficiently lock certain resources while performing table lookups, which can cause the cache results to... Read more
Affected Products : freebsd- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2139
PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.... Read more
Affected Products : pavsta_auto_site- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025