Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-06-09 CVE-2005-1909 Unspecified vulnerability in Software602 602Lan Suite 2004
The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a "</pre><!-" sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting (XSS) vulnerability.
network
software602
4.3
2005-06-09 CVE-2005-1908 Security Bypass vulnerability in Perception Liteweb 2.5
Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.
network
low complexity
perception
7.5
2005-06-09 CVE-2005-1905 Privilege Escalation vulnerability in Kaspersky LAB products
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.
local
low complexity
kaspersky-lab
7.2
2005-06-09 CVE-2005-1902 Directory Traversal vulnerability in E-Post Corporation Spa-Pro Mail Atsolomon 4.00
Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via ..
local
low complexity
e-post-corporation
3.6
2005-06-09 CVE-2005-1901 Cross-Site Scripting vulnerability in Sawmill
Multiple cross-site scripting (XSS) vulnerabilities in Sawmill before 7.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the username in the Add User window or (2) the license key in the Licensing page.
network
sawmill
4.3
2005-06-09 CVE-2005-1900 Security Bypass vulnerability in Sawmill
Sawmill before 7.1.6 allows remote attackers to bypass authentication and (1) gain administrative privileges or (2) add a license.
network
low complexity
sawmill
7.5
2005-06-09 CVE-2005-1899 Remote Denial of Service vulnerability in Rakkarsoft RakNet
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.
network
low complexity
rakkarsoft
5.0
2005-06-09 CVE-2005-1898 Information Disclosure vulnerability in PHPThumb Arbitrary File
The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.
network
low complexity
phpthumb
5.0
2005-06-09 CVE-2005-1897 Remote Security vulnerability in Flexcast Audio Video Streaming Server
Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.
network
low complexity
flexcast
critical
10.0
2005-06-09 CVE-2005-1896 Directory Traversal vulnerability in Flatnuke 2.5.3
Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.
network
low complexity
flatnuke
5.0