Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1311 Cross-Site Scripting vulnerability in Yappa-NG
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
yappa-ng
4.3
2005-05-02 CVE-2005-1309 Cross-Site Scripting vulnerability in Eaden Mckee Bblog 0.7.4
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
network
eaden-mckee
4.3
2005-05-02 CVE-2005-1305 Remote Security vulnerability in Hyper.Cgi
The hyper.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
network
low complexity
hyper-cgi
5.0
2005-05-02 CVE-2005-1292 Cross-Site Scripting vulnerability in CartWIZ
Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.
4.3
2005-05-02 CVE-2005-1290 Cross-Site Scripting vulnerability in phpBB
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.
network
phpbb-group
4.3
2005-05-02 CVE-2005-1282 HTML Injection vulnerability in Argosoft Mail Server 1.8.7.6
Multiple cross-site scripting (XSS) vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the src parameter in an IMG tag, (2) User settings, or (3) Address book input boxes in the webmail interface.
network
argosoft
4.3
2005-05-02 CVE-2005-1280 Denial Of Service vulnerability in tcpdump RSVP Decoding Routines
The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.
network
low complexity
lbl
5.0
2005-05-02 CVE-2005-1279 Denial Of Service vulnerability in tcpdump LDP Decoding Routines
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.
network
low complexity
lbl
5.0
2005-05-02 CVE-2005-1278 Denial Of Service vulnerability in tcpdump ISIS Decoding Routines
The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.
network
low complexity
lbl
5.0
2005-05-02 CVE-2005-1245 HTML Tidy Cross-Site Scripting vulnerability in MediaWiki
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
mediawiki
4.3