Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2735
Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : phpgraphy- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2722
Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.... Read more
Affected Products : php_weblog- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2727
Home Ftp Server 1.0.7 stores sensitive user information and server information in the same directory as the user's home directory, which allows remote authenticated users to obtain sensitive information by obtaining ftpmembers.lst and ftpsettings.lst.... Read more
Affected Products : home_ftp_server- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2733
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.... Read more
Affected Products : simple_php_blog- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2737
Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : photopost_php_pro- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2732
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message.... Read more
Affected Products : awstats- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2734
Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : gallery- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2736
Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.... Read more
Affected Products : yapig- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2719
Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784.... Read more
Affected Products : ventrilo- Published: Aug. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2716
The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.... Read more
Affected Products : affix- Published: Aug. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2717
PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.... Read more
Affected Products : webcalendar- Published: Aug. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2718
Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.... Read more
Affected Products : mplayer- Published: Aug. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2696
IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "P... Read more
Affected Products : lotus_notes- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2693
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.... Read more
Affected Products : cvs- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2698
Cross-site scripting (XSS) vulnerability in browse.php in Nephp Publisher Enterprise 3.04 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded keywords parameter.... Read more
Affected Products : nephp_publisher_enterprise- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2699
Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator... Read more
Affected Products : phpkit- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2697
SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282.... Read more
Affected Products : mybulletinboard- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2695
Unspecified vulnerability in the SSL certificate checking functionality in Cisco CiscoWorks Management Center for IDS Sensors (IDSMC) 2.0 and 2.1, and Monitoring Center for Security (Security Monitor or Secmon) 1.1 through 2.0 and 2.1, allows remote attac... Read more
- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2694
Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that contains an entry with a long file name.... Read more
Affected Products : winace- Published: Aug. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2692
Multiple SQL injection vulnerabilities in RunCMS 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) addquery and (2) subquery parameters to the newbb plus module, the forum parameter to (3) newtopic.php, (4) edit.php, or ... Read more
Affected Products : runcms- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025