Latest CVE Feed
-
7.5
HIGHCVE-2005-3558
PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters.... Read more
Affected Products : oste- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3557
Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3551
toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.... Read more
Affected Products : toendacms- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3581
GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.... Read more
Affected Products : gdal- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3544
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : xmb- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3585
SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter.... Read more
Affected Products : phpwebthings- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-3527
Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.... Read more
Affected Products : linux_kernel- Published: Nov. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3524
Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.... Read more
Affected Products : linux-ftpd-ssl- Published: Nov. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3523
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.... Read more
Affected Products : gpsdrive- Published: Nov. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3521
SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.... Read more
Affected Products : e107- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3520
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_... Read more
Affected Products : mysource- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3522
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.... Read more
Affected Products : manageengine_netflow_analyzer- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3519
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_P... Read more
Affected Products : mysource- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3124
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : thttpd- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3516
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.... Read more
Affected Products : chipmunk_directory- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3507
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.... Read more
Affected Products : cutenews- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3511
Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter... Read more
Affected Products : spymac_web_os- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3518
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.... Read more
Affected Products : punbb- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3510
Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.... Read more
Affected Products : tomcat- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3514
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.... Read more
Affected Products : chipmunk_forum- Published: Nov. 06, 2005
- Modified: Apr. 03, 2025