Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-17 CVE-2005-4313 SQL Injection vulnerability in Almondsoft Almond Personals 4.05
SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
almondsoft
7.5
2005-12-17 CVE-2005-4312 SQL Injection vulnerability in AlmondSoft Almond Classifieds
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
almondsoft
7.5
2005-12-17 CVE-2005-4311 Cross-Site Scripting vulnerability in DCForum DCBoard Script Page Parameter
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.
network
dcscripts
4.3
2005-12-17 CVE-2005-4310 Authentication Authorization Bypass vulnerability in SSH Tectia Server 5.0.0A/5.0.0F/5.0.0T
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.
network
low complexity
ssh
7.5
2005-12-17 CVE-2005-4309 SQL Injection vulnerability in EZUpload
SQL injection vulnerability in ezUpload Pro 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
network
low complexity
scriptscenter
7.5
2005-12-17 CVE-2005-4308 Remote File Include vulnerability in EZUpload
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.
network
low complexity
scriptscenter
7.5
2005-12-17 CVE-2005-4307 Cross-Site Scripting vulnerability in ScareCrow
Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.
4.3
2005-12-17 CVE-2005-4306 Cross-Site Scripting vulnerability in SiteNet BBS
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.
network
focalmedia-net
4.3
2005-12-17 CVE-2005-4305 Cross-Site Scripting vulnerability in Edgewall Software Trac 0.9/0.9.1/0.9.2
Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.
4.3
2005-12-17 CVE-2005-4304 Input Validation vulnerability in EZDatabase
index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message.
network
low complexity
indexcor
5.0