Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-24 CVE-2005-1716 Information Disclosure vulnerability in Topo 2.2/2.2.178
TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.
network
low complexity
ej3
5.0
2005-05-24 CVE-2005-1715 Index.PHP Cross-Site Scripting vulnerability in EJ3 Topo 2.2/2.2.178
Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section.
network
ej3
4.3
2005-05-24 CVE-2005-1714 Unspecified vulnerability in Netwin Surgemail 3.0C2
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
netwin
4.3
2005-05-24 CVE-2005-1713 Unspecified vulnerability in S9Y Serendipity 0.8
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
network
s9y
4.3
2005-05-24 CVE-2005-1712 Remote Security vulnerability in SY9 Serendipity 0.8
Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.
network
low complexity
sy9
7.5
2005-05-24 CVE-2005-1711 Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.
network
low complexity
clam-anti-virus gibraltar squid
7.5
2005-05-24 CVE-2005-1710 Unspecified vulnerability in Bluecoat Reporter 7.1.1
Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page.
network
bluecoat
4.3
2005-05-24 CVE-2005-1709 HTML Injection vulnerability in Bluecoat Reporter 7.1.1
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.
network
low complexity
bluecoat
7.5
2005-05-24 CVE-2005-1708 Remote Privilege Escalation vulnerability in Bluecoat Reporter 7.1.1
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.
local
low complexity
bluecoat
4.6
2005-05-24 CVE-2005-1707 Unspecified vulnerability in Gentoo Linux Webapp-Config 1.10
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.
local
low complexity
gentoo
4.6