Weekly Vulnerabilities Reports > September 19 to 25, 2005
Overview
84 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 34 high severity vulnerabilities. This weekly summary report vulnerabilities in 62 products from 51 vendors including Mozilla, Jelsoft, Phpmyfaq, Bugada Andrea, and Opera. Vulnerabilities are notably categorized as "SQL Injection", "Cross-site Scripting", "Code", "Permissions, Privileges, and Access Controls", and "Improper Restriction of Operations within the Bounds of a Memory Buffer".
- 72 reported vulnerabilities are remotely exploitables.
- 4 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 83 reported vulnerabilities are exploitable by an anonymous user.
- Mozilla has the most reported vulnerabilities, with 8 reported vulnerabilities.
- Francisco Burzi has the most reported critical vulnerabilities, with 1 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
2 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-21 | CVE-2005-3016 | Francisco Burzi | Remote Security vulnerability in PHP-Nuke Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors. | 10.0 |
2005-09-24 | CVE-2005-3051 | Igor Pavlov | Buffer Errors vulnerability in Igor Pavlov 7-Zip 3.13/4.23/4.26Beta Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block. | 9.3 |
34 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-24 | CVE-2005-3052 | Jportal | SQL-Injection vulnerability in jportal SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php. | 7.5 |
2005-09-24 | CVE-2005-3045 | MY Little Homepage | SQL Injection vulnerability in MY Little Homepage MY Little Forum 1.3/1.5 SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field. | 7.5 |
2005-09-23 | CVE-2005-2705 | Mozilla | Integer Overflow vulnerability in Mozilla Browser/Firefox JavaScript Engine Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code. | 7.5 |
2005-09-23 | CVE-2005-2702 | Mozilla | Unspecified vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters. | 7.5 |
2005-09-23 | CVE-2005-2701 | Mozilla | Heap Overflow vulnerability in Mozilla Browser/Firefox XBM Image Processing Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag. | 7.5 |
2005-09-22 | CVE-2005-3043 | Mall23 | SQL Injection vulnerability in Mall23 AddItem.ASP SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter. | 7.5 |
2005-09-22 | CVE-2005-3042 | Usermin Webmin | Remote PAM Authentication Bypass vulnerability in Webmin / Usermin miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return). | 7.5 |
2005-09-22 | CVE-2005-3039 | Mall23 | SQL Injection vulnerability in Mall23 Infopage.ASP SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter. | 7.5 |
2005-09-22 | CVE-2005-3034 | Compuware | Authentication Bypass vulnerability in Compuware Driverstudio 2.7/3.0Beta2 Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session. | 7.5 |
2005-09-22 | CVE-2005-3033 | Cambridge Computer Corporation | Denial-Of-Service vulnerability in Cambridge Computer Corporation Vxweb 1.1.4 Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | 7.5 |
2005-09-22 | CVE-2005-3032 | Cambridge Computer Corporation | Remote Buffer Overflow vulnerability in Cambridge Computer Corporation Vxtftpsrv 1.7 Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument. | 7.5 |
2005-09-22 | CVE-2005-3031 | Cambridge Computer Corporation | Remote Security vulnerability in Cambridge Computer Corporation Vxftpsrv 0.9.7 Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name. | 7.5 |
2005-09-21 | CVE-2005-3029 | Ahnlab | Remote Buffer Overflow vulnerability in Ahnlab V3 Virusblock 2005, V3Net and V3Pro 2004 Stack-based buffer overflow in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to execute arbitrary code via a long filname in an ACE archive. | 7.5 |
2005-09-21 | CVE-2005-3024 | Jelsoft | SQL-Injection vulnerability in vBulletin Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] parameter to email.php, (13) help[0] parameter to help.php, the (14) limitnumber or (15) limitstart parameter to user.php, the (16) usertitleid or (17) ids parameters to usertitle.php, (18) rvt[0] parameter to language.php, (19) keep[0] parameter to phrase.php, (20) dostyleid parameter to template.php, (21) thread[forumid] parameter to thread.php, or (22) usertools.php. | 7.5 |
2005-09-21 | CVE-2005-3022 | Jelsoft | SQL-Injection vulnerability in vBulletin Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to help.php, (7) rvt parameter to language.php, (8) keep parameter to phrase.php, or (9) updateprofilepic parameter to usertools.php. | 7.5 |
2005-09-21 | CVE-2005-3019 | Jelsoft | Moderator And Administrator SQL Injection vulnerability in VBulletin Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php. | 7.5 |
2005-09-21 | CVE-2005-3010 | Cutephp | Unspecified vulnerability in Cutephp Cutenews Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php. | 7.5 |
2005-09-21 | CVE-2005-3008 | Amar Sagoo | Remote Python Code Execution vulnerability in Amar Sagoo Tofu 0.2 Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes. | 7.5 |
2005-09-21 | CVE-2005-3005 | Helpdesk Software | Authentication Bypass vulnerability in Helpdesk Software Hesk 0.92/0.93 Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie. | 7.5 |
2005-09-21 | CVE-2005-3004 | Interakt | SQL Injection vulnerability in Interakt MX Shop 3.2.0 SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php. | 7.5 |
2005-09-21 | CVE-2005-3003 | Noosoftware | SQL-Injection vulnerability in NooTopList SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters. | 7.5 |
2005-09-21 | CVE-2005-2764 | Openttd | Denial-Of-Service vulnerability in Openttd 0.4.0.1 Multiple buffer overflows in OpenTTD before 0.4.0.1 allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. | 7.5 |
2005-09-21 | CVE-2005-0139 | SGI | Permissions, Privileges, and Access Controls vulnerability in SGI Irix 6.5.25/6.5.26/6.5.27 Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities. | 7.5 |
2005-09-21 | CVE-2005-0138 | SGI | Code vulnerability in SGI Irix 6.5.25/6.5.26/6.5.27 rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. | 7.5 |
2005-09-21 | CVE-2005-2662 | Masqmail | Local Privilege Escalation vulnerability in MasqMail masqmail before 0.2.18 allows remote attackers to execute arbitrary commands via crafted e-mail addresses that are not properly sanitized when creating a failed delivery message. | 7.5 |
2005-09-20 | CVE-2005-2920 | Clam Anti Virus | Buffer Overflow vulnerability in ClamAV UPX Compressed Executable Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable. | 7.5 |
2005-09-20 | CVE-2005-2998 | Bugada Andrea | Remote Security vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30 PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files. | 7.5 |
2005-09-20 | CVE-2005-2996 | Symantec Veritas | Unspecified vulnerability in Symantec Veritas Storage Exec and Storagecentral Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls. | 7.5 |
2005-09-20 | CVE-2005-2968 | Mozilla | Unspecified vulnerability in Mozilla Firefox and Mozilla Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash. | 7.5 |
2005-09-20 | CVE-2005-2989 | Deluxebb | SQL Injection vulnerability in Deluxebb 1.0/1.05 Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php. | 7.5 |
2005-09-20 | CVE-2005-2987 | Digital Scribe | SQL Injection vulnerability in Digital Scribe Digital Scribe 1.4 SQL injection vulnerability in login.php in Digital Scribe 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 7.5 |
2005-09-20 | CVE-2005-2986 | Ahnlab | SQL Injection vulnerability in Ahnlab V3 Virusblock 2005, V3Net and V3Pro 2004 The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoControl commands, which allows remote attackers to gain privileges. | 7.5 |
2005-09-20 | CVE-2005-2985 | Aewebworks | SQL Injection vulnerability in AEwebworks Aedating 3.2/4.0 SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter. | 7.5 |
2005-09-20 | CVE-2005-2983 | Oracle | SQL Injection vulnerability in Oracle Reports 1.00 SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes. | 7.5 |
38 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-24 | CVE-2005-3046 | Phpmyfaq | SQL Injection vulnerability in PHPmyfaq 1.5.1 SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field. | 6.8 |
2005-09-20 | CVE-2005-2994 | IBM | Cross-Site Scripting vulnerability in Rational ClearQuest Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS). | 6.8 |
2005-09-24 | CVE-2005-3048 | Phpmyfaq | Directory Traversal vulnerability in PHPmyfaq 1.5.1 Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. | 6.4 |
2005-09-23 | CVE-2005-2706 | Mozilla | Unspecified vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla. | 6.4 |
2005-09-24 | CVE-2005-3050 | Phpmyfaq | Information Disclosure vulnerability in PHPmyfaq 1.5.1 PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message. | 5.0 |
2005-09-24 | CVE-2005-3049 | Phpmyfaq | Unspecified vulnerability in PHPmyfaq 1.5.1 PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file. | 5.0 |
2005-09-23 | CVE-2005-2707 | Mozilla | Unspecified vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks. | 5.0 |
2005-09-23 | CVE-2005-2704 | Mozilla | Unspecified vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface. | 5.0 |
2005-09-23 | CVE-2005-2703 | Mozilla | Code Injection vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting. | 5.0 |
2005-09-22 | CVE-2005-3041 | Opera | Unspecified vulnerability in Opera Browser Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads." | 5.0 |
2005-09-22 | CVE-2005-3040 | TAC | Directory Traversal vulnerability in Vista 3.0/4.0 Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter. | 5.0 |
2005-09-22 | CVE-2005-3038 | Hosting Controller | Information Disclosure vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.3 Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability." | 5.0 |
2005-09-22 | CVE-2005-3035 | Compuware | Remote Reboot vulnerability in Compuware Driverstudio 2.7/3.0Beta2 Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110. | 5.0 |
2005-09-21 | CVE-2005-3030 | Ahnlab | Directory Traversal vulnerability in Ahnlab V3 Virusblock 2005, V3Net and V3Pro 2004 Directory traversal vulnerability in the archive decompression library in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to write arbitrary files via a .. | 5.0 |
2005-09-21 | CVE-2005-3027 | Sybari | Unspecified vulnerability in Sybari Antigen 8.0 Sybari Antigen 8.0 SR2 does not properly filter SMTP messages, which allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment". | 5.0 |
2005-09-21 | CVE-2005-3026 | Alstrasoft | Directory Traversal vulnerability in EPay Pro Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. | 5.0 |
2005-09-21 | CVE-2005-3018 | Apple | Unspecified vulnerability in Apple Safari Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL. | 5.0 |
2005-09-21 | CVE-2005-3006 | Opera | Multiple vulnerability in Opera Web Browser Mail Client The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachment filenames. | 5.0 |
2005-09-20 | CVE-2005-3002 | Xclusive Software | Denial-Of-Service vulnerability in Xclusive-Software Mccs 1.0 Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet. | 5.0 |
2005-09-20 | CVE-2005-2919 | Clam Anti Virus | Code vulnerability in Clam Anti-Virus Clamav libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable. | 5.0 |
2005-09-20 | CVE-2005-2999 | Bugada Andrea | Remote Security vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30 PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php. | 5.0 |
2005-09-20 | CVE-2005-2997 | Bugada Andrea | Directory Traversal vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30 Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir parameter to (2) htm.php or (3) html.php. | 5.0 |
2005-09-20 | CVE-2005-2988 | HP | Information Disclosure vulnerability in LaserJet 2430 HP LaserJet 2430, and possibly other printers that use Jetdirect controls, stores information about recently printed documents without proper protection, which could allow remote attackers to obtain sensitive information via SNMP. | 5.0 |
2005-09-22 | CVE-2005-3036 | Ttxn | Local Security vulnerability in Ttxn File Transfer Anywhere 3.01 File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges. | 4.6 |
2005-09-21 | CVE-2005-3013 | Suse | Local Buffer Overflow vulnerability in Suse Linux 9.3 Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users to execute arbitrary code via a long Loc entry. | 4.6 |
2005-09-20 | CVE-2005-2984 | Data Center Resources | Unspecified vulnerability in Data Center Resources Avocent Ccm48502.1Firmware Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access the serial port. | 4.6 |
2005-09-24 | CVE-2005-3047 | Phpmyfaq | Cross-Site Scripting vulnerability in PHPmyfaq 1.5.1 Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php. | 4.3 |
2005-09-22 | CVE-2005-3037 | Handy Address Book | Cross-Site Scripting vulnerability in Handy Address Book Handy Address Book Server 1.1 Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL. | 4.3 |
2005-09-21 | CVE-2005-3025 | Jelsoft | Cross-Site Scripting vulnerability in vBulletin Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php. | 4.3 |
2005-09-21 | CVE-2005-3023 | Jelsoft | Cross-Site Scripting vulnerability in vBulletin Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.php, (12) replacement.php, (13) template.php, (14) template.php, (15) usergroup.php, or (16) usertitle.php. | 4.3 |
2005-09-21 | CVE-2005-3020 | Jelsoft | Cross-Site Scripting vulnerability in VBulletin Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php. | 4.3 |
2005-09-21 | CVE-2005-3017 | Content2Web | Cross-Site Scripting vulnerability in Content2Web 1.0.1 PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS). | 4.3 |
2005-09-21 | CVE-2005-3015 | IBM | Cross-Site Scripting vulnerability in IBM Lotus Domino and Lotus Domino Enterprise Server Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters. | 4.3 |
2005-09-21 | CVE-2005-3014 | Ensim | HTML Injection vulnerability in Ensim Webppliance 3.0/3.1/3.1.1 Cross-site scripting (XSS) vulnerability in Ensim webplliance allows remote attackers to inject arbitrary web script or HTML via the Login (OCW_login_username) field. | 4.3 |
2005-09-21 | CVE-2005-3009 | Cutephp | Cross-Site Scripting vulnerability in CuteNews Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php. | 4.3 |
2005-09-20 | CVE-2005-3000 | Bugada Andrea | Cross-Site Scripting vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30 Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or (3) mess[31] parameters. | 4.3 |
2005-09-20 | CVE-2005-2982 | Compaq | Cross-Site Scripting vulnerability in Compaq Compaqhttpserver 2.1 Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page. | 4.3 |
2005-09-20 | CVE-2005-2981 | Orionserver | Cross-Site Scripting vulnerability in Orionserver Orion Application Server 1.3.8/1.4.5 Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page. | 4.3 |
10 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-09-20 | CVE-2005-2995 | Bacula | Denial-Of-Service vulnerability in Bacula bacula 1.36.3 and earlier allows local users to modify or read sensitive files via symlink attacks on (1) the temporary file used by autoconf/randpass when openssl is not available, or (2) the mtx.[PID] temporary file in mtx-changer.in. | 3.6 |
2005-09-21 | CVE-2005-3007 | Opera | Injection vulnerability in Opera Browser Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content. | 2.6 |
2005-09-21 | CVE-2005-3021 | Jelsoft | File-Upload vulnerability in vBulletin image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action. | 2.1 |
2005-09-21 | CVE-2005-3012 | Simplecdr X | Unspecified vulnerability in Simplecdr-X 1.3.3 The MasterDataCD::createImage function in masterdatacd.cpp for SimpleCDR-X 1.3.3 creates the .temp temporary directory with insecure permissions, which allows local users to read sensitive ISO images. | 2.1 |
2005-09-21 | CVE-2005-2663 | Masqmail | Local Privilege Escalation vulnerability in MasqMail masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file. | 2.1 |
2005-09-20 | CVE-2005-3001 | SUN | Denial-Of-Service vulnerability in SUN Solaris 10.0 Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors. | 2.1 |
2005-09-20 | CVE-2005-2991 | Ncompress | Local Security vulnerability in ncompress ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970. | 2.1 |
2005-09-20 | CVE-2005-2990 | Linecontrol | Local Password Disclosure vulnerability in Linecontrol Java Client 0.8 AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files. | 2.1 |
2005-09-20 | CVE-2005-2993 | HP | Remote Denial Of Service vulnerability in HP-UX FTPD Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang). | 1.7 |
2005-09-21 | CVE-2005-3011 | GNU | Link Following vulnerability in GNU Texinfo 4.8 The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files. | 1.2 |