Latest CVE Feed
-
7.5
HIGHCVE-2005-1169
Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.... Read more
Affected Products : mafia_blog- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0831
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.... Read more
Affected Products : php-post_web_forum- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1289
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.... Read more
Affected Products : e-cart- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0907
Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.php, (3) the lang parameter to index.php, (4) the search... Read more
Affected Products : shopping_cart- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0938
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.... Read more
Affected Products : ublog_reload- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0920
Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : bugtracker.net- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0956
Multiple SQL injection vulnerabilities in index.php in InterAKT MX Kart 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_man parameter.... Read more
Affected Products : mx_kart- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0080
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1352
Cross-site scripting (XSS) vulnerability in the ad.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : ad.cgi- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0073
Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.... Read more
Affected Products : sympa- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0311
Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.... Read more
Affected Products : ingate_firewall- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0071
vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.... Read more
Affected Products : vdr- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0137
Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."... Read more
Affected Products : linux_kernel- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0060
Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-0056
Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Do... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0086
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0055
Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corr... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0301
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.... Read more
Affected Products : comersus_backoffice_lite- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0571
admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.... Read more
Affected Products : punbb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0051
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulne... Read more
Affected Products : windows_xp- Published: May. 02, 2005
- Modified: Apr. 03, 2025