Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-10-14 CVE-2005-3209 Local Security vulnerability in Aenovo Aenovo, Aenovoshop and Aenovowysi
Aenovo products (1) aeNovo, (2) aeNovoShop, and (3) aeNovoWYSI store password information in plaintext in the (a) control, (b) content, and (c) page tables, which allows attackers with database access to obtain those passwords and gain privileges.
local
low complexity
aenovo
4.6
2005-10-14 CVE-2005-3208 SQL Injection vulnerability in Aenovo Aenovo, Aenovoshop and Aenovowysi
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execute arbitrary SQL code via (a) the password parameter in control.asp, and (b) the strSQL parameter in search.asp, which can enable XSS attacks in resulting error messages.
network
aenovo
6.8
2005-10-14 CVE-2005-3207 Remote Denial Of Service vulnerability in Oracle Forms Servlet TLS Listener
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS listener stop) via a userid parameter that contains a STOP command.
network
low complexity
oracle
5.0
2005-10-14 CVE-2005-3206 Remote Denial Of Service vulnerability in Oracle Database Server 9.0.2.4
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command.
network
low complexity
oracle
5.0
2005-10-14 CVE-2005-3205 Cross-Site Scripting vulnerability in Oracle Database Server 9.0.2.4
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
network
oracle CWE-79
3.5
2005-10-14 CVE-2005-3204 Cross-Site Scripting vulnerability in Oracle Application Server and Oracle9I
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
network
oracle
4.3
2005-10-14 CVE-2005-3203 Unspecified vulnerability in Oracle Html DB 1.3/1.3.6
The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges.
local
low complexity
oracle
4.6
2005-10-14 CVE-2005-3202 Cross-Site Scripting vulnerability in Oracle HTML DB 1.3/1.3.6
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters.
network
oracle
6.8
2005-10-14 CVE-2005-3201 SQL Injection vulnerability in Utopia News Pro
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.
network
low complexity
utopia-software
7.5
2005-10-14 CVE-2005-3200 Cross-Site Scripting vulnerability in Utopia Software Utopia News PRO 1.1.3/1.1.4
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.
network
utopia-software
4.3