Latest CVE Feed
-
7.5
HIGHCVE-2005-2614
Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php.... Read more
Affected Products : discuz- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2604
index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message.... Read more
Affected Products : my_image_gallery- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2607
PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters.... Read more
Affected Products : simplicity_of_upload- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2616
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.... Read more
Affected Products : ezupload- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2605
Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.... Read more
Affected Products : lasso_professional_server- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2599
Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges.... Read more
Affected Products : connectivity- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2598
Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroline/scorm/scormdocument.php, (2) move arbitrary files via... Read more
Affected Products : dokeos- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2592
Unknown vulnerability in Parlano MindAlign 5.0 and later versions allows remote attackers to bypass authentication via unknown vectors.... Read more
Affected Products : mindalign- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2611
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allo... Read more
- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2600
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.... Read more
Affected Products : fudforum- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2597
AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privileges by replacing ACSD.exe with a malicious program.... Read more
Affected Products : aol_client_software- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2610
Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : vegadns- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2101
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.... Read more
Affected Products : kde- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2615
Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.... Read more
Affected Products : eqdkp- Published: Aug. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2102
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.... Read more
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2358
EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).... Read more
Affected Products : navisphere_manager- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2097
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf ... Read more
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2561
Multiple SQL injection vulnerabilities in MYFAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the Theme parameter to (1) affichagefaq.php3, (2) choixsoustheme.php3, (3) consultation.php3, (4) insfaq.php3, (5) inssoustheme.php3, (6) inst... Read more
Affected Products : myfaq- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2357
Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.... Read more
Affected Products : navisphere_manager- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2568
Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly bracket) characters, which are processed by the PHP eval func... Read more
Affected Products : syscp- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025