Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-11-22 | CVE-2005-3766 | Remote Security vulnerability in Exponent Exponent CMS 0.96.3 and later versions stores sensitive user pages under the web document root with insufficient access control even though certain permissions are specified, which allows attackers to access the pages by browsing uploaded files. | 5.0 |
2005-11-22 | CVE-2005-3763 | Information Disclosure vulnerability in Exponent Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. | 5.0 |
2005-11-22 | CVE-2005-3761 | Unspecified vulnerability in Exponent Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or HTML via (1) Javascript in forms produced by the form generator or (2) the parameters to the installer. network exponent | 4.3 |
2005-11-22 | CVE-2005-3759 | Cross-Site Scripting vulnerability in Horde Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments. | 5.8 |
2005-11-22 | CVE-2005-3758 | Remote vulnerability in Google Mini Search Appliance and Search Appliance Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet. network google | 4.3 |
2005-11-22 | CVE-2005-3756 | Remote vulnerability in Google Mini Search Appliance and Search Appliance Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports. | 5.0 |
2005-11-22 | CVE-2005-3755 | Remote vulnerability in Google Mini Search Appliance and Search Appliance Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a relative path from a style sheet directory, then comparing the resulting error messages. | 5.0 |
2005-11-22 | CVE-2005-3754 | Remote vulnerability in Google Mini Search Appliance and Search Appliance Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message. network google | 4.3 |
2005-11-22 | CVE-2005-3751 | Cross-Site Scripting vulnerability in Pound HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with conflicting Content-length and Transfer-encoding headers. network apsis | 4.3 |
2005-11-22 | CVE-2005-3747 | Information Exposure vulnerability in Mortbay Jetty Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. | 5.0 |