Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-01-10 | CVE-2004-1215 | Remote vulnerability in Burut Kreed 1.5 Kreed 1.05 and earlier allows remote attackers to cause a denial of service (server disconnect) via a long UDP packet, which causes a "message too long" socket error. | 5.0 |
2005-01-10 | CVE-2004-1213 | Cross-Site Scripting vulnerability in Advanced Guestbook Advanced Guestbook 2.2/2.3.1 Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter. network advanced-guestbook | 6.8 |
2005-01-10 | CVE-2004-1212 | Remote Directory Traversal vulnerability in Blog Torrent Blog Torrent Preview 0.8 Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. | 5.0 |
2005-01-10 | CVE-2004-1210 | HTML Injection vulnerability in Ipcop 1.4.1 Cross-site scripting (XSS) vulnerability in proxylog.dat in IPCop 1.4.1 and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) part variables. network ipcop | 6.8 |
2005-01-10 | CVE-2004-1209 | Remote Security vulnerability in Payflow Link Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase. | 5.0 |
2005-01-10 | CVE-2004-1207 | Remote Denial Of Service vulnerability in SeriousSam SeriousEngine User Management The Serious engine, as used in (1) Alpha Black Zero Intrepid Protocol 1.04 and earlier, (2) Nitro family, and (3) Serious Sam Second Encounter 1.07 allows remote attackers to cause a denial of service (server crash) via a large number of UDP join requests that exceeds the maximum player limit, as originally reported for Alpha Black Zero. | 5.0 |
2005-01-10 | CVE-2004-1206 | Directory Traversal vulnerability in PNTresMailer Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. | 5.0 |
2005-01-10 | CVE-2004-1205 | codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message. | 5.0 |
2005-01-10 | CVE-2004-1203 | Information Disclosure vulnerability in PHPcms 1.1.9/1.2.0/1.2.1 parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path. | 5.0 |
2005-01-10 | CVE-2004-1202 | Cross-Site Scripting vulnerability in PHPcms 1.1.9/1.2/1.2.1 Cross-site scripting (XSS) vulnerability in parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to inject arbitrary web script or HTML via the file parameter. network phpcms | 6.8 |