Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-11 CVE-2005-1498 Input Validation vulnerability in Mybloggie 2.1.1/2.1.2
Multiple cross-site scripting (XSS) vulnerabilities in myBloggie 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) year parameter in viewmode.php, or the (2) cat_id, (3) month_no, or (4) post_id parameter in index.php, which are not properly sanitized before they are displayed in an error message.
network
mywebland
4.3
2005-05-11 CVE-2005-1497 Information Disclosure vulnerability in Mywebland Mybloggie 2.1.1
index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.
network
low complexity
mywebland
5.0
2005-05-11 CVE-2005-1496 Privilege Escalation vulnerability in Oracle Application Server and Oracle10G
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
local
low complexity
oracle
4.6
2005-05-11 CVE-2005-1495 Buffer Overflow vulnerability in Oracle Application Server, Oracle10G and Oracle9I
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
network
low complexity
oracle
7.5
2005-05-11 CVE-2005-1494 Cross-Site Scripting vulnerability in MegaBook Admin.CGI EntryID
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.
network
megabook
4.3
2005-05-11 CVE-2005-1493 Directory Traversal vulnerability in Dead Pirate Software Simplecam 1.2
Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.
network
low complexity
dead-pirate-software
5.0
2005-05-11 CVE-2005-1491 Local Security vulnerability in Mail Server
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.
local
low complexity
icewarp merak
4.6
2005-05-11 CVE-2005-1490 Local Security vulnerability in Mail Server
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.
local
low complexity
icewarp merak
2.1
2005-05-11 CVE-2005-1489 Remote Security vulnerability in Mail Server
Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.
network
low complexity
icewarp merak
5.0
2005-05-11 CVE-2005-1488 Cross-Site Scripting vulnerability in Mail Server
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.html, (2) addressaction.html, (3) the Signature field to settings.html, or (4) the Shared calendars to calendarsettings.html.
local
icewarp merak
1.9