Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-05 CVE-2005-2135 SQL-Injection vulnerability in Etoshop Dynamic BIZ Website Builder Quickweb 1.0
SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.
network
low complexity
etoshop
7.5
2005-07-05 CVE-2005-2134 Denial-Of-Service vulnerability in NetBSD
The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.
local
low complexity
netbsd
2.1
2005-07-05 CVE-2005-2115 Denial-Of-Service vulnerability in Soldier Of Fortune 2
Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.
network
low complexity
raven-software
5.0
2005-07-05 CVE-2005-2114 Denial-Of-Service vulnerability in Firefox
Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.
network
low complexity
mozilla
5.0
2005-07-05 CVE-2005-2113 SQL-Injection vulnerability in Xoops
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.
network
low complexity
xoops
7.5
2005-07-05 CVE-2005-2112 Cross-Site Scripting vulnerability in Xoops
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.
network
xoops
4.3
2005-07-05 CVE-2005-2111 Remote Security vulnerability in Community Link Pro Web Editor
login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.
network
low complexity
community-link-pro-web-editor
7.5
2005-07-05 CVE-2005-2110 Information Disclosure vulnerability in WordPress
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message.
network
low complexity
wordpress
5.0
2005-07-05 CVE-2005-2109 Denial-Of-Service vulnerability in WordPress
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
network
low complexity
wordpress
5.0
2005-07-05 CVE-2005-2108 SQL-Injection vulnerability in WordPress
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.
network
low complexity
wordpress
7.5