Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1634
Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.p... Read more
Affected Products : jgs-portal- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1639
SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.... Read more
Affected Products : sigma_isp_manager- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1631
booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.... Read more
Affected Products : booby- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1640
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass i... Read more
Affected Products : ignitionserver- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1642
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.... Read more
Affected Products : burning_board- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1626
Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.... Read more
Affected Products : pico_server- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1612
SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via the TID parameter.... Read more
Affected Products : openbb- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1613
Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web script or HTML via the reverse parameter in a list action.... Read more
Affected Products : openbb- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1622
Cross-site scripting (XSS) vulnerability in productsByCategory.asp in MetaCart e-Shop allows remote attackers to inject arbitrary web script or HTML via the strCatalog_NAME parameter.... Read more
Affected Products : metacart_e-shop- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1593
Cross-site scripting (XSS) vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : shoppingcart- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1596
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.... Read more
Affected Products : sbx- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1607
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.... Read more
Affected Products : remote_cart- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1608
Multiple unknown vulnerabilities in the Blocks module in Spidean AutoTheme 1.7 and AT-Lite for PostNuke have unknown impact.... Read more
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1604
PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.... Read more
Affected Products : php_advanced_transfer_manager- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1600
A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.... Read more
Affected Products : libtomcrypt- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1618
The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrup... Read more
Affected Products : messenger- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1595
CodeThat ShoppingCart 1.3.1 stores config.ini under the web root, which allows remote attackers to obtain sensitive information via a direct request.... Read more
Affected Products : shoppingcart- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1615
viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.... Read more
Affected Products : ultimate_php_board- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1606
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.... Read more
Affected Products : h-sphere_winbox- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1594
SQL injection vulnerability in catalog.php for CodeThat ShoppingCart 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : shoppingcart- Published: May. 16, 2005
- Modified: Apr. 03, 2025