Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1963
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.... Read more
Affected Products : cerberus_helpdesk- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2027
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.... Read more
Affected Products : vertical_horizon-2402s- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2005
Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.... Read more
Affected Products : ultimate_php_board- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1722
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.... Read more
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1266
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.... Read more
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1306
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."... Read more
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2000
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query ... Read more
Affected Products : pafiledb- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1996
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.... Read more
Affected Products : bitrix_site_manager- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2002
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.... Read more
Affected Products : mambo- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2041
Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).... Read more
Affected Products : virobot_linux_server- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1997
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.... Read more
Affected Products : mcgallery- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1999
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter i... Read more
Affected Products : pafiledb- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1995
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.... Read more
Affected Products : bitrix_site_manager- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2001
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.... Read more
Affected Products : pafiledb- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1998
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.... Read more
Affected Products : mcgallery- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1214
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_98se windows_me windows_2000_terminal_services- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1216
Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.... Read more
Affected Products : isa_server- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1205
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.... Read more
Affected Products : windows_2003_server- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1207
Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.... Read more
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1211
Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.... Read more
Affected Products : internet_explorer- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025