Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2021
Cross-site scripting (XSS) vulnerability in cPanel 9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the user parameter in the login page.... Read more
Affected Products : cpanel- Published: Jun. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1992
The XMLRPC server in utils.rb for the ruby library (libruby) 1.8 sets an invalid default value that prevents "security protection" using handlers, which allows remote attackers to execute arbitrary commands.... Read more
Affected Products : ruby- Published: Jun. 20, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-1993
Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.... Read more
Affected Products : sudo- Published: Jun. 20, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2007
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.... Read more
Affected Products : trac- Published: Jun. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2039
Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands.... Read more
Affected Products : nanoblogger- Published: Jun. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0773
Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (W... Read more
- Published: Jun. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2024
Vipul Razor Agents (razor-agents) before 2.70 allows remote attackers to cause a denial of service via (1) certain "unusual HTML messages" or (2) "certain malformed headers" such as Content-Type.... Read more
Affected Products : razor-agents- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2023
The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.... Read more
Affected Products : suse_linux- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2006
JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or (2) with a % (percent) before a filename, which reveals the contents of the... Read more
Affected Products : jboss- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2022
Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.... Read more
- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2004
Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, (2) id or (3) page parameter to viewtopic.php, id parame... Read more
Affected Products : ultimate_php_board- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2043
Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php.... Read more
Affected Products : apache_distribution- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2008
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).... Read more
Affected Products : webserver- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2029
amaroK Web Frontend 1.3 stores the globals.inc file under the web root without a .php extension and insufficient access control, which allows remote attackers to obtain the database username and password via a direct request to the file.... Read more
Affected Products : web_frontend- Published: Jun. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1975
Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters... Read more
Affected Products : 1two- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1949
The eping_validaddr function in functions.php for the ePing plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the eping_host parameter.... Read more
Affected Products : e107- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2003
Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.... Read more
Affected Products : ultimate_php_board- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2042
Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.... Read more
Affected Products : ajax-spell- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1962
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.... Read more
Affected Products : cerberus_helpdesk- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1970
Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.... Read more
Affected Products : pcanywhere- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025