Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-06-29 CVE-2005-2070 Remote Denial Of Service Weakness in Sendmail Milter
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.
network
low complexity
sendmail
5.0
2005-06-29 CVE-2005-2067 SQL Injection vulnerability in ASPNuke Article.ASP
SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.
network
low complexity
asp-nuke
7.5
2005-06-29 CVE-2005-2066 SQL Injection vulnerability in Asp-Nuke 0.80
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.
network
low complexity
asp-nuke
7.5
2005-06-29 CVE-2005-2065 Unspecified vulnerability in Asp-Nuke 0.80
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.
network
low complexity
asp-nuke
5.0
2005-06-29 CVE-2005-2064 Cross-Site Scripting vulnerability in Asp-Nuke 0.80
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.
network
low complexity
asp-nuke
5.0
2005-06-29 CVE-2005-2063 Cross-Site Scripting vulnerability in Active web Softwares Activebuyandsell 6.2
Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.
4.3
2005-06-29 CVE-2005-2062 SQL Injection vulnerability in Active web Softwares Activebuyandsell 6.2
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5) buyer.asp, or Keyword field in search.asp.
network
low complexity
active-web-softwares
7.5
2005-06-29 CVE-2005-2061 Remote Security vulnerability in UBB.threads
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.
network
low complexity
ubbcentral
5.0
2005-06-29 CVE-2005-2060 Remote Security vulnerability in UBB.threads
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.
network
low complexity
ubbcentral
5.0
2005-06-29 CVE-2005-2059 Cross-Site Request Forgery (CSRF) vulnerability in Ubbcentral Ubb.Threads
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.
network
low complexity
ubbcentral CWE-352
6.5