Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1817
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.... Read more
Affected Products : invision_board- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1788
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.... Read more
Affected Products : hosting_controller- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1837
Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.... Read more
Affected Products : fortinet_firewall- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1822
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error... Read more
Affected Products : x-cart- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1810
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.... Read more
Affected Products : wordpress- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1823
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id ... Read more
Affected Products : x-cart- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1816
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.... Read more
Affected Products : invision_board- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1794
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.... Read more
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1765
syscall in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform, when running in 32-bit compatibility mode, allows local users to cause a denial of service (kernel hang) via crafted arguments.... Read more
Affected Products : linux_kernel- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1783
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the result... Read more
Affected Products : bookreview- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1781
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).... Read more
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
8.4
HIGHCVE-2005-1831
Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able t... Read more
Affected Products : sudo- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1775
Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a large nickname.... Read more
Affected Products : terminator_3_war_of_the_machines- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1773
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available.... Read more
Affected Products : listserv- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1772
Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.... Read more
Affected Products : terminator_3_war_of_the_machines- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1780
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : active_news_manager- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1776
Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.... Read more
Affected Products : cnedra- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1785
SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : zongg- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1833
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4... Read more
Affected Products : mybulletinboard- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1770
Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.... Read more
Affected Products : avast_antivirus- Published: May. 31, 2005
- Modified: Apr. 03, 2025