Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1006 Cross-site Scripting vulnerability in Sonicwall Soho Firmware 5.1.7.0
Multiple cross-site scripting (XSS) vulnerabilities in SonicWALL SOHO 5.1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) the user login name, which is not filtered when the administrator views the log file.
network
sonicwall CWE-79
4.3
2005-05-02 CVE-2005-1004 Unspecified vulnerability in Profitcode Payprocart 3.0
Cross-site scripting (XSS) vulnerability in usrdetails.php in ProfitCode PayProCart 3.0 allows remote attackers to inject arbitrary web script or HTML via the sgnuptype parameter.
network
profitcode
4.3
2005-05-02 CVE-2005-1002 Unspecified vulnerability in Logics Software Log-Ft
logwebftbs2000.exe in Logics Software File Transfer (LOG-FT) allows remote attackers to read arbitrary files via modified (1) VAR_FT_LANG and (2) VAR_FT_TMPL parameters.
network
low complexity
logics-software
5.0
2005-05-02 CVE-2005-1001 Information Disclosure vulnerability in Francisco Burzi PHP-Nuke 7.6
PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via direct requests to (1) the Surveys module with the file parameter set to comments or (2) 3D-Fantasy/theme.php, which leaks the full pathname of the web server in a PHP error message.
network
low complexity
francisco-burzi
5.0
2005-05-02 CVE-2005-1000 Unspecified vulnerability in Francisco Burzi PHP-Nuke 7.6
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the bid parameter to the EmailStats op in banners.pgp, (2) the ratenum parameter in the TopRated and MostPopular actions in the Web_Links module, (3) the ttitle parameter in the viewlinkdetails, viewlinkeditorial, viewlinkcomments, and ratelink actions in the Web_Links module, or (4) the username parameter in the Your_Account module.
network
francisco-burzi
4.3
2005-05-02 CVE-2005-0998 Information Disclosure vulnerability in Francisco Burzi PHP-Nuke 7.6
The Web_Links module for PHP-Nuke 7.6 allows remote attackers to obtain sensitive information via an invalid show parameter, which triggers a division by zero PHP error that leaks the full pathname of the server.
network
low complexity
francisco-burzi
5.0
2005-05-02 CVE-2005-0996 Unspecified vulnerability in Francisco Burzi PHP-Nuke 7.6
Multiple SQL injection vulnerabilities in the Downloads module for PHP-Nuke 7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the email or url parameters in the Add function, (2) the min parameter in the viewsdownload function, or (3) the min parameter in the search function.
network
low complexity
francisco-burzi
5.0
2005-05-02 CVE-2005-0995 Input Validation vulnerability in Early Impact Productcart 2.7
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirectUrl parameter to NewCust.asp, (3) the country parameter to storelocator_submit.asp, or (4) the error parameter to techErr.asp.
network
early-impact
4.3
2005-05-02 CVE-2005-0993 Local Buffer Overflow vulnerability in SCO OpenServer NWPrint Command Line Argument
Buffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument.
local
low complexity
sco
4.6
2005-05-02 CVE-2005-0992 Cross-Site Scripting vulnerability in PHPMyAdmin Convcharset
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.
network
phpmyadmin
4.3