Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-06-16 CVE-2005-2027 Information Disclosure vulnerability in Vertical Horizon VH-2402S 2.05.00/2.05.08.01/2.05.09.07
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.
network
low complexity
enterasys
5.0
2005-06-16 CVE-2005-2026 Remote Security vulnerability in Vertical Horizon VH-2402S 2.05.00/2.05.08.01/2.05.09.07
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.
network
low complexity
enterasys
7.5
2005-06-16 CVE-2005-2005 Information Disclosure vulnerability in Ultimate PHP Board
Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat.
network
low complexity
ultimate-php-board
5.0
2005-06-16 CVE-2005-2003 Information Disclosure vulnerability in Ultimate PHP Board Ultimate PHP Board 1.9.6Gold
Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.
network
low complexity
ultimate-php-board
5.0
2005-06-16 CVE-2005-1975 HTML Injection vulnerability in Annuaire 1Two 1.0
Multiple cross-site scripting (XSS) vulnerabilities in Annuaire 1Two 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter to index.php, or the (2) site_id, (3) nom, (4) email, or (5) commentaire parameters in commentaires.php.
network
annuaire
4.3
2005-06-16 CVE-2005-1974 Privilege Escalation vulnerability in Sun Java Runtime Environment
Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to themselves and gain privileges.
network
high complexity
sun
5.1
2005-06-16 CVE-2005-1973 Privilege Escalation vulnerability in Sun Java Web Start
Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.
network
high complexity
sun
5.1
2005-06-16 CVE-2005-1971 Directory Traversal vulnerability in Interactivephp Fusionbb 11Beta
Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.
network
low complexity
interactivephp
7.5
2005-06-16 CVE-2005-1970 Local Privileged Command Execution vulnerability in Symantec PCAnywhere
Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature.
local
low complexity
symantec
7.2
2005-06-16 CVE-2005-1967 SQL-Injection vulnerability in Productcart Ecommerce
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) idcategory parameter to viewPrd.asp, (2) lid parameter to editCategories.asp, (3) icd parameter to modCustomCardPaymentOpt.asp, or (4) idccr parameter to OptionFieldsEdit.asp.
network
low complexity
early-impact
7.5