Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1309 Cross-Site Scripting vulnerability in Eaden Mckee Bblog 0.7.4
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
network
eaden-mckee
4.3
2005-05-02 CVE-2005-1305 Remote Security vulnerability in Hyper.Cgi
The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
network
low complexity
hyper-cgi
5.0
2005-05-02 CVE-2005-1304 The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.
network
low complexity
citat-pl
7.5
2005-05-02 CVE-2005-1302 SQL Injection vulnerability in Swsoft Confixx 3.0.6/3.0.8/Pro3
SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.
network
low complexity
swsoft
7.5
2005-05-02 CVE-2005-1293 SQL-Injection vulnerability in Storeportal 2.63
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.
network
low complexity
storeportal
7.5
2005-05-02 CVE-2005-1292 Cross-Site Scripting vulnerability in CartWIZ
Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.
4.3
2005-05-02 CVE-2005-1290 Cross-Site Scripting vulnerability in phpBB
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.
network
phpbb-group
4.3
2005-05-02 CVE-2005-1289 Unspecified vulnerability in E-Cart 20041.1
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and possibly (2) cat parameters.
network
low complexity
e-cart
7.5
2005-05-02 CVE-2005-1288 Remote Security vulnerability in ACS Blog
inc_login_check.asp ACS Blog 0.8 through 1.1.3 allows remote attackers to gain administrator privileges via the "in" value in a cookie.
network
low complexity
asp-press
7.5
2005-05-02 CVE-2005-1286 Local Security vulnerability in Softwin Bitdefender Antivirus Professionalplus8/Standard8
Unquoted Windows search path vulnerability in BitDefender 8 allows local users to prevent BitDefender from starting by creating a malicious C:\program.exe, possibly due to the lack of quoting of the full pathname when executing a process.
local
high complexity
softwin
1.2