Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1313
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : passwd- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1324
Multiple cross-site scripting (XSS) vulnerabilities in index.php for phpMyVisites allow remote attackers to inject arbitrary web script or HTML via the (1) part, (2) per, or (3) site parameters.... Read more
Affected Products : phpmyvisites- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0333
LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.... Read more
Affected Products : lanchat_pro_revival- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0463
Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.... Read more
Affected Products : ulog-php- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1165
Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data.... Read more
Affected Products : yager_game- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1074
SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.... Read more
Affected Products : radbids- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1362
Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) ch... Read more
Affected Products : metacart2- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1066
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1374
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.... Read more
Affected Products : perlshop- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1000
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular acti... Read more
Affected Products : php-nuke- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1090
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.... Read more
Affected Products : maxthon- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1356
Cross-site scripting (XSS) vulnerability in includer.cgi script in The Includer allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : includer.cgi- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0921
Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.... Read more
Affected Products : outlook_connector- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1095
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : membership_manager_pro- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1238
By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.... Read more
Affected Products : iseries_as_400- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0841
SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via... Read more
Affected Products : phpmyfamily- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0897
PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code.... Read more
Affected Products : e-store_kit-2- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0746
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.... Read more
Affected Products : ichain- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0811
The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs.... Read more
Affected Products : notifylink- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1163
Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.... Read more
Affected Products : yager_game- Published: May. 02, 2005
- Modified: Apr. 03, 2025