Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-06 CVE-2005-2161 Unspecified vulnerability in PHPbb Group PHPbb 2.0.16
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
network
phpbb-group
4.3
2005-07-06 CVE-2005-2160 Cleartext Storage of Sensitive Information vulnerability in Ipswitch Imail 2006
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
network
low complexity
ipswitch CWE-312
7.5
2005-07-06 CVE-2005-2159 Remote Buffer Overflow vulnerability in Planetdns Planetfileserver 2.0.1.3
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
network
low complexity
planetdns
5.0
2005-07-06 CVE-2005-2158 Remote Security vulnerability in Jboss Jbpm 2.0
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.
network
low complexity
jboss
7.5
2005-07-06 CVE-2005-2157 Remote Security vulnerability in Nabocorp Nabopoll 1.2
PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.
network
low complexity
nabocorp
5.0
2005-07-06 CVE-2005-2156 SQL Injection vulnerability in PHPnews 1.2.5
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
network
low complexity
phpnews
7.5
2005-07-06 CVE-2005-2155 Remote Security vulnerability in Easyphpcalendar 6.1.5
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
network
low complexity
easyphpcalendar
7.5
2005-07-06 CVE-2005-2154 Input Validation vulnerability in OSTicket
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.
network
low complexity
osticket
7.5
2005-07-06 CVE-2005-2153 Input Validation vulnerability in OSTicket
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.
network
low complexity
osticket
7.5
2005-07-06 CVE-2005-2152 SQL-Injection vulnerability in Geeklog
SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.
network
low complexity
geeklog
7.5