Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1180 Remote Security vulnerability in Francisco Burzi PHP-Nuke 7.6
HTTP Response Splitting vulnerability in the Surveys module in PHP-Nuke 7.6 allows remote attackers to spoof web content and poison web caches via hex-encoded CRLF ("%0d%0a") sequences in the forwarder parameter.
network
low complexity
francisco-burzi
5.0
2005-05-02 CVE-2005-1179 SNMP Authentication Bypass vulnerability in Xerox MicroServer
Unknown vulnerability in Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 through 1.001.02.084, and others, related to SNMP authentication, allows remote attackers to modify system configuration, a different vulnerability than CVE-2005-0703.
network
low complexity
xerox
5.0
2005-05-02 CVE-2005-1178 SQL-Injection vulnerability in Forms And Reports
SQL injection vulnerability in Oracle Forms 10g allows remote attackers to execute arbitrary SQL commands via the Query/Where feature.
network
low complexity
oracle
7.5
2005-05-02 CVE-2005-1177 Denial-Of-Service vulnerability in Usermin
Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact.
network
low complexity
usermin webmin
critical
10.0
2005-05-02 CVE-2005-1176 Information Disclosure vulnerability in AIX
Race condition in JFS2 on AIX 5.2 and 5.3, when deleting a file while I/O is still occurring for that file, may write data to a different file, which could leak sensitive information.
local
high complexity
ibm
1.2
2005-05-02 CVE-2005-1173 Unspecified vulnerability in Pmsoftware Simple web Server 1.0
Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.
network
low complexity
pmsoftware
7.5
2005-05-02 CVE-2005-1172 HTML Injection vulnerability in Coppermine Photo Gallery X-Forwarded-For Logging
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
network
coppermine
4.3
2005-05-02 CVE-2005-1171 Remote Mod.PHP Cross-Site Scripting vulnerability in Datenbank Module For PHPBB
Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.
4.3
2005-05-02 CVE-2005-1170 Unspecified vulnerability in Datenbank Module Datenbank Module
SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
datenbank-module
7.5
2005-05-02 CVE-2005-1169 Authentication Bypass vulnerability in Mafia Blog 4Beta
Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.
network
low complexity
mafia
7.5