Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-08-03 CVE-2005-2422 Cross-Site Scripting vulnerability in Beehive Forum Webtag
Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.
network
beehive-forum
4.3
2005-08-03 CVE-2005-2421 SQL Injection vulnerability in Beehive Forum Webtag
Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.
network
low complexity
beehive-forum
7.5
2005-08-03 CVE-2005-2420 Remote Command Execution vulnerability in FTPLocate
flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.
network
low complexity
ftplocate
critical
10.0
2005-08-03 CVE-2005-2419 Unspecified vulnerability in ECI Telecom B-Focus Router 312
B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg.
network
low complexity
eci-telecom
7.5
2005-08-03 CVE-2005-2417 Input Validation vulnerability in Contrexx
Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.
network
low complexity
astalavista-it-engineering
5.0
2005-08-03 CVE-2005-2416 Input Validation vulnerability in Contrexx
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.
4.3
2005-08-03 CVE-2005-2415 Input Validation vulnerability in Contrexx
Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.
network
low complexity
astalavista-it-engineering
7.5
2005-08-03 CVE-2005-2414 Denial-Of-Service vulnerability in Xpcom
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.
network
high complexity
xpcom
2.6
2005-08-03 CVE-2005-2413 Remote File Include vulnerability in Atomic Photo Album Apa_PHPInclude.INC.PHP
PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.
network
low complexity
atomic-photo-album
5.0
2005-08-03 CVE-2005-2412 Remote File Include vulnerability in PHPFirstpost Block.PHP
PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.
network
low complexity
php-firstpost
5.0