Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-24 CVE-2005-1738 Local Format String vulnerability in Iron Bars Shell Iron Bars Shell 0.3A/0.3B/0.3C
Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call.
network
low complexity
iron-bars-shell
critical
10.0
2005-05-24 CVE-2005-1737 Denial-Of-Service vulnerability in Electricmonk Proms 0.11
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.
network
low complexity
electricmonk
7.5
2005-05-24 CVE-2005-1736 Remote Security vulnerability in Proms
PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.
network
low complexity
electricmonk
7.5
2005-05-24 CVE-2005-1735 Unspecified vulnerability in Electricmonk Proms
Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
electricmonk
4.3
2005-05-24 CVE-2005-1734 Unspecified vulnerability in Electricmonk Proms
Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
electricmonk
7.5
2005-05-24 CVE-2005-1733 Remote Security vulnerability in Cookie Cart
Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.
network
low complexity
metro-marketing
5.0
2005-05-24 CVE-2005-1732 Remote Security vulnerability in Cookie Cart
Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.
network
low complexity
metro-marketing
5.0
2005-05-24 CVE-2005-1719 Unspecified vulnerability in Alwil Avast Antivirus
Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.
network
low complexity
alwil
7.5
2005-05-24 CVE-2005-1718 Denial-Of-Service vulnerability in LS Games WAR Times 1.03
Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.
network
low complexity
ls-games
5.0
2005-05-24 CVE-2005-1717 Remote Denial of Service vulnerability in Zyxel Prestige 650R-31 3.40Ko.1
ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.
network
low complexity
zyxel
5.0