Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-05-02 | CVE-2005-1092 | Local Authentication Credentials Disclosure vulnerability in Light Speed Technologies DeluxeFTP Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges. | 7.2 |
2005-05-02 | CVE-2005-1091 | Information Disclosure vulnerability in Maxthon Web Browser Plug-in API Security ID Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page. | 7.5 |
2005-05-02 | CVE-2005-1090 | Directory Traversal vulnerability in Maxthon 1.2.0/1.2.1 Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files. | 6.4 |
2005-05-02 | CVE-2005-1088 | Privilege Escalation vulnerability in Dameware Development Mini Remote Control and NT Utilities Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights. | 7.2 |
2005-05-02 | CVE-2005-1086 | Remote Buffer Overflow vulnerability in AN An-Httpd 1.42N Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header. | 6.4 |
2005-05-02 | CVE-2005-1085 | Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML. network aewebworks | 4.3 |
2005-05-02 | CVE-2005-1084 | Unspecified vulnerability in Aewebworks Aedating 3.2 SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter. | 7.5 |
2005-05-02 | CVE-2005-1083 | Unspecified vulnerability in Aewebworks Aedating 3.2 index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter. | 5.0 |
2005-05-02 | CVE-2005-1081 | Multiple vulnerability in Azerbaijan Development Group Azdgdating 1.1.0 Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. network azerbaijan-development-group | 4.3 |
2005-05-02 | CVE-2005-1080 | Directory Traversal vulnerability in Sun J2SE Software Development Kit Java Archive Tool Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. | 5.0 |