Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-06 CVE-2005-2165 Remote Security vulnerability in GlobalNoteScript
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
network
low complexity
globalnotescript
7.5
2005-07-06 CVE-2005-2164 SQL-Injection vulnerability in Covide Groupware-Crm Covide 5.2
SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
network
low complexity
covide-groupware-crm
7.5
2005-07-06 CVE-2005-2163 Cross-Site Scripting vulnerability in Autoindex PHP Script 1.5.2
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
network
autoindex
4.3
2005-07-06 CVE-2005-2162 Remote Security vulnerability in Levcgi.Com Myguestbook 0.6.1
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
network
low complexity
levcgi-com
5.0
2005-07-06 CVE-2005-2161 Unspecified vulnerability in PHPbb Group PHPbb 2.0.16
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
network
phpbb-group
4.3
2005-07-06 CVE-2005-2160 Cleartext Storage of Sensitive Information vulnerability in Ipswitch Imail 2006
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
network
low complexity
ipswitch CWE-312
7.5
2005-07-06 CVE-2005-2159 Remote Buffer Overflow vulnerability in Planetdns Planetfileserver 2.0.1.3
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
network
low complexity
planetdns
5.0
2005-07-06 CVE-2005-2158 Remote Security vulnerability in Jboss Jbpm 2.0
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.
network
low complexity
jboss
7.5
2005-07-06 CVE-2005-2157 Remote Security vulnerability in Nabocorp Nabopoll 1.2
PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.
network
low complexity
nabocorp
5.0
2005-07-06 CVE-2005-2156 SQL Injection vulnerability in PHPnews 1.2.5
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
network
low complexity
phpnews
7.5