Latest CVE Feed
-
5.0
MEDIUMCVE-2005-4219
setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which might allow attackers to obtain this information via a direct request to setting.php. NOTE: on a properly configured web server, it wou... Read more
Affected Products : innovative_cms- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4240
SQL injection vulnerability in search.php in VCD-db 0.98 and earlier allows remote attackers to execute arbitrary SQL commands via the by parameter.... Read more
Affected Products : vcd-db- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4252
Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4215
Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).... Read more
Affected Products : motorola_cable_modem- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4225
Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameter... Read more
Affected Products : mybloggie- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4227
Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_m... Read more
Affected Products : dcp-portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4226
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters... Read more
Affected Products : phpwebthings- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4221
SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL commands via the (1) PHPSESSID (session ID) or (2) REQUEST_URI (query string).... Read more
Affected Products : arab_portal- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4237
Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module.... Read more
Affected Products : mysqlauction- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4217
Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privileges.... Read more
Affected Products : mac_os_x_server- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4232
SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and di... Read more
Affected Products : jamit_job_board- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4222
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.... Read more
Affected Products : guestserver- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4216
The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application crash) via a malformed request with a single character to port 1111.... Read more
Affected Products : flash_media_server- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4213
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via the phpcoinsessid cookie.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4212
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2831
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use ... Read more
- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4251
Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.... Read more
Affected Products : mcgallery_pro- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4228
Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, a... Read more
Affected Products : phpwebgallery- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4230
SQL injection vulnerability in poll.php in Link Up Gold 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the number parameter.... Read more
Affected Products : link_up_gold- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4211
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.... Read more
Affected Products : phpcoin- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025