Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0617 SQL-Injection vulnerability in Postnuke Software Foundation Postnuke 0.750/0.760Rc2
SQL injection vulnerability in dl-search.php in PostNuke 0.750 and 0.760-RC2 allows remote attackers to execute arbitrary SQL commands via the show parameter.
network
low complexity
postnuke-software-foundation
7.5
2005-05-02 CVE-2005-0615 SQL-Injection vulnerability in Postnuke Software Foundation Postnuke 0.760Rc2
Multiple SQL injection vulnerabilities in (1) index.php, (2) modules.php, or (3) admin.php in PostNuke 0.760-RC2 allow remote attackers to execute arbitrary SQL code via the catid parameter.
network
low complexity
postnuke-software-foundation
7.5
2005-05-02 CVE-2005-0614 Remote Security vulnerability in phpBB
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
network
low complexity
phpbb-group
7.5
2005-05-02 CVE-2005-0612 Remote Default Community String vulnerability in Cisco IP/VC Videoconferencing System SNMP
Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration.
network
low complexity
cisco
7.5
2005-05-02 CVE-2005-0601 Remote vulnerability in Cisco Application and Content Networking System
Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.
network
low complexity
cisco
7.5
2005-05-02 CVE-2005-0595 Remote Buffer Overflow vulnerability in Working Resources Inc. Badblue 2.55
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
network
low complexity
working-resources-inc
7.5
2005-05-02 CVE-2005-0575 Remote Buffer Overflow vulnerability in Stormy Studios KNet
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request.
network
low complexity
stormy-studios
7.5
2005-05-02 CVE-2005-0569 Remote Input Validation vulnerability in Punbb 1.2.1
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to register.php, (2) change email feature in profile.php, (3) posts or (4) topics parameter to moderate.php.
network
low complexity
punbb
7.5
2005-05-02 CVE-2005-0567 Local File Include vulnerability in PHPmyadmin 2.6.1
Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code.
network
low complexity
phpmyadmin
7.5
2005-05-02 CVE-2005-0565 Remote Security vulnerability in Phpwebsite
The Announce module in phpWebSite 0.10.0 and earlier allows remote attackers to execute arbitrary PHP code by setting the Image field to reference a PHP file whose name contains a .gif.php extension.
network
low complexity
phpwebsite
7.5