Weekly Vulnerabilities Reports > December 5 to 11, 2005

Overview

157 new vulnerabilities reported during this period, including 3 critical vulnerabilities and 72 high severity vulnerabilities. This weekly summary report vulnerabilities in 130 products from 108 vendors including Efiction Project, Web4Future, Lyris Technologies INC, PHP WEB, and SUN. Vulnerabilities are notably categorized as "SQL Injection", "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Permissions, Privileges, and Access Controls", "Cross-site Scripting", and "Numeric Errors".

  • 145 reported vulnerabilities are remotely exploitables.
  • 10 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 152 reported vulnerabilities are exploitable by an anonymous user.
  • Efiction Project has the most reported vulnerabilities, with 8 reported vulnerabilities.
  • HP has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

3 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-12-08 CVE-2005-4090 HP IPSec Unauthorized Remote Access vulnerability in HP-UX

Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact.

10.0
2005-12-05 CVE-2005-4007 Redgraphic Remote Security vulnerability in Redgraphic Sapid CMS 1.2.3/1.2.3.02

Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/controller/user_request_analysis.inc.php and (2) usr/xml/ddc/authorization.xml.

10.0
2005-12-11 CVE-2005-4156 Mambo Denial-Of-Service vulnerability in Mambo Open Source 4.5

Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.

9.4

72 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-12-11 CVE-2005-4153 GNU Denial Of Service vulnerability in GNU Mailman 2.1.4/2.1.5/2.1.6

Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573.

7.8
2005-12-11 CVE-2005-4152 Soti Unspecified vulnerability in Soti Pocket Controller-Professional 5.0

Soti Pocket Controller-Professional 5.0 allows remote attackers to turn off, reboot, or hard reset a PDA via a series of initialization, command, and reset packets sent to port 5492.

7.8
2005-12-06 CVE-2005-4039 Web4Future Directory Traversal vulnerability in Web4Future Portal Solutions

Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter.

7.8
2005-12-05 CVE-2005-4014 PHP WEB Denial-Of-Service vulnerability in PHP web Statistik 1.4

stat.php in PHP Web Statistik 1.4 allows remote attackers to cause a denial of service (CPU consumption) via a large lastnumber value.

7.8
2005-12-05 CVE-2005-3993 Mailenable Denial-Of-Service vulnerability in MailEnable Enterprise

Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands.

7.8
2005-12-11 CVE-2005-4174 Efiction Project Input Validation vulnerability in eFiction

eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php.

7.5
2005-12-11 CVE-2005-4171 Efiction Project Input Validation vulnerability in Efiction Project Efiction 1.1

The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.

7.5
2005-12-11 CVE-2005-4170 Efiction Project Input Validation vulnerability in Efiction Project Efiction 1.1

SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.

7.5
2005-12-11 CVE-2005-4169 Efiction Project Input Validation vulnerability in Efiction Project Efiction 1.0

Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php.

7.5
2005-12-11 CVE-2005-4168 Efiction Project Input Validation vulnerability in Efiction Project Efiction 1.0/1.1/2.0

Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username.

7.5
2005-12-11 CVE-2005-4165 ASP DEV Cross-Site Scripting vulnerability in ASP-DEV XM Forum Forum.ASP

Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the "Search For" field in search.asp.

7.5
2005-12-11 CVE-2005-4164 Widgetmonkey SQL-Injection vulnerability in Widgetmonkey PHP-Addressbook 1.2

SQL injection vulnerability in view.php in PHP-addressbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2005-12-11 CVE-2005-4159 Simple Machines Unspecified vulnerability in Simple Machines Simple Machines Forum

** DISPUTED ** NOTE: this issue has been disputed by the vendor and third parties.

7.5
2005-12-11 CVE-2005-4157 Kerio Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account that has been disabled.
7.5
2005-12-11 CVE-2005-4155 Adaptive Technology Resource Centre Unspecified vulnerability in Adaptive Technology Resource Centre Atutor 1.5.1Pl2

registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check.

7.5
2005-12-11 CVE-2005-3532 Double Precision Incorporated Unspecified vulnerability in Double Precision Incorporated Courier Mail Server

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

7.5
2005-12-10 CVE-2005-4144 Lyris SQL Injection vulnerability in Lyris ListManager

Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace.

7.5
2005-12-10 CVE-2005-4143 Lyris SQL Injection vulnerability in Lyris ListManager

SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL.

7.5
2005-12-10 CVE-2005-4142 Lyris Technologies INC Unspecified vulnerability in Lyris Technologies INC Listmanager

The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter.

7.5
2005-12-10 CVE-2005-3651 Ethereal Group Stack Buffer Overflow vulnerability in Ethereal OSPF Protocol Dissection

Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets.

7.5
2005-12-09 CVE-2005-4141 Aspmforum SQL Injection vulnerability in ASPMForum

Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.

7.5
2005-12-09 CVE-2005-4140 Website Baker SQL Injection vulnerability in Website Baker 2.5.2/2.6

SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field.

7.5
2005-12-09 CVE-2005-4139 Thwboard Input Validation vulnerability in Thwboard Beta 2.8

Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php.

7.5
2005-12-09 CVE-2005-4137 FAD Solutions Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2

SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter.

7.5
2005-12-09 CVE-2005-4135 Simplemedia Remote Arbitrary Command Execution vulnerability in Simplebbs 1.0.6/1.0.7/1.1

Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.

7.5
2005-12-09 CVE-2005-4132 Contenido Remote Command Execution vulnerability in Contenido Contendio 4.5.2Alpha/4.5.6Beta/4.6.0

Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors.

7.5
2005-12-09 CVE-2005-4130 Realnetworks Unspecified vulnerability in Realnetworks Realplayer

** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208.

7.5
2005-12-09 CVE-2005-4126 Realnetworks Remote Code Execution vulnerability in Real Networks RealPlayer

** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208.

7.5
2005-12-08 CVE-2005-4094 Docebolms Unspecified vulnerability in Docebolms 2.0.4

connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to execute arbitrary PHP by using the FileUpload command to upload a file that appears to be an image but contains PHP script.

7.5
2005-12-08 CVE-2005-4092 Apple Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes and Quicktime

Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and possibly other vectors involving media files.

7.5
2005-12-08 CVE-2005-4088 W2B SQL Injection vulnerability in PHPForumPro

SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and (2) day parameters.

7.5
2005-12-08 CVE-2005-4087 Sugarcrm Remote and Local File Include vulnerability in Sugarcrm Sugar Suite 3.5/4.0Beta

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.

7.5
2005-12-08 CVE-2005-4081 Alisveristr Unspecified vulnerability in Alisveristr E-Commerce

Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages.

7.5
2005-12-08 CVE-2005-4073 Cfmagic SQL Injection vulnerability in Cfmagic Magic List PRO

SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter.

7.5
2005-12-08 CVE-2005-4071 Cfmagic SQL Injection vulnerability in Cfmagic Magic Forum Personal

Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm.

7.5
2005-12-08 CVE-2005-3192 Xpdf Buffer Errors vulnerability in Xpdf 3.0.1

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

7.5
2005-12-07 CVE-2005-4065 Edgewall Software SQL Injection vulnerability in Edgewall Software Trac Search Module

SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

7.5
2005-12-07 CVE-2005-4064 Alan Ward SQL Injection vulnerability in Alan Ward A-Faq 1.0

Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp.

7.5
2005-12-07 CVE-2005-4059 Locazo Unspecified vulnerability in Locazo Locazolist

SQL injection vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to execute arbitrary SQL commands via the q parameter.

7.5
2005-12-07 CVE-2005-4058 Saralblog SQL Injection vulnerability in Saralblog 1/1Beta

SQL injection vulnerability in saralblog 1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to viewprofile.php.

7.5
2005-12-07 CVE-2005-4056 Jonathan Beckett Unspecified vulnerability in Jonathan Beckett Pluggedout Nexus 0.1

SQL injection vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) Location, (2) Last Name, and (3) First Name parameters.

7.5
2005-12-07 CVE-2005-4055 Cars Portal SQL Injection vulnerability in Cars Portal

SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters.

7.5
2005-12-07 CVE-2005-4054 Pluggedout SQL Injection vulnerability in Pluggedout Blog 1.9.5

SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter.

7.5
2005-12-07 CVE-2005-4050 Multi Tech Systems Remote Buffer Overflow vulnerability in MultiTech MultiVOIP INVITE

Buffer overflow in multiple Multi-Tech Systems MultiVOIP devices with firmware before x.08 allows remote attackers to execute arbitrary code via a long INVITE field in a Session Initiation Protocol (SIP) packet.

7.5
2005-12-07 CVE-2005-4049 Netart Media Unspecified vulnerability in Netart Media Blog System 1.2

Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.

7.5
2005-12-07 CVE-2005-4048 Ffmpeg Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ffmpeg

Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes.

7.5
2005-12-07 CVE-2005-4045 SUN Unspecified vulnerability in SUN Java Communications Services Delegated Administrator 6

Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif.

7.5
2005-12-07 CVE-2005-2931 Ipswitch Remote Format String vulnerability in Ipswitch Imail Server and Ipswitch Collaboration Suite

Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands.

7.5
2005-12-06 CVE-2005-4043 Hobosworld SQL Injection vulnerability in Hobosworld HobSR

SQL injection vulnerability in view.php in Hobosworld HobSR 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) arrange and (2) p parameters.

7.5
2005-12-06 CVE-2005-4040 Tawbaware SQL Injection vulnerability in Tawbaware Filelister

SQL injection vulnerability in FileLister 0.51 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameters, possibly the searchwhat parameter to definesearch.jsp.

7.5
2005-12-06 CVE-2005-4038 Web4Future SQL Injection vulnerability in Web4Future Portal Solutions Comentarii.PHP

SQL injection vulnerability in comentarii.php in Web4Future Portal Solutions News Portal allows remote attackers to execute arbitrary SQL commands via the idp parameter.

7.5
2005-12-06 CVE-2005-4037 Web4Future SQL Injection vulnerability in Web4Future Affiliate Manager PRO Functions.PHP

SQL injection vulnerability in functions.php in Web4Future Affiliate Manager PRO 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.

7.5
2005-12-06 CVE-2005-4035 Web4Future SQL Injection vulnerability in Web4Future eCommerce Enterprise Edition

Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.

7.5
2005-12-06 CVE-2005-4034 Web4Future SQL Injection vulnerability in Web4Future Edating Professional 5

Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php.

7.5
2005-12-06 CVE-2005-4031 Mediawiki Remote Code Execution vulnerability in MediaWiki User Language

Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function.

7.5
2005-12-05 CVE-2005-4027 Simplemedia SQL Injection vulnerability in Simplemedia Simplebbs 1.1

SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.

7.5
2005-12-05 CVE-2005-4025 Help Desk Reloaded Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user.
7.5
2005-12-05 CVE-2005-4020 Widget Press SQL-Injection vulnerability in Widget Imprint

SQL injection vulnerability in create.php in Widget Imprint 1.0.26 and earlier allows remote attackers to execute arbitrary SQL commands via the product_id parameter.

7.5
2005-12-05 CVE-2005-4019 Relative Real Estate Systems SQL Injection vulnerability in Relative Real Estate Systems

SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter.

7.5
2005-12-05 CVE-2005-4018 Landshop SQL Injection vulnerability in SAMEDIA Landshop

SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.

7.5
2005-12-05 CVE-2005-4016 Widget Press SQL Injection vulnerability in Widget Press Widget Property 1.1.19

SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php.

7.5
2005-12-05 CVE-2005-4011 Codewalkers SQL Injection vulnerability in Codewalkers Ltwcalendar

SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2005-12-05 CVE-2005-4010 Sensation Designs SQL Injection vulnerability in KBase Express

SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php.

7.5
2005-12-05 CVE-2005-4009 PHP Lite SQL-Injection vulnerability in PHP Lite Calendar Express 2.0/2.2

Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php.

7.5
2005-12-05 CVE-2005-4008 JAX Calendar SQL Injection vulnerability in JAX Calendar JAX Calendar 1.34

SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameters.

7.5
2005-12-05 CVE-2005-4006 Redgraphic Improper Authentication vulnerability in Redgraphic Sapid CMS 1.2.3/1.2.3.02

SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfile.php, and (5) edit.php.

7.5
2005-12-05 CVE-2005-4005 PHP Fusion SQL Injection vulnerability in PHP Fusion PHP Fusion 6.00.109

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Search and Sort option to messages.php.

7.5
2005-12-05 CVE-2005-4003 Asps Cross-Site Scripting vulnerability in Absolute Shopping Package Solutions Shopping Cart 2.1/2.9D

Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp.

7.5
2005-12-05 CVE-2005-4001 Phpyellow SQL Injection vulnerability in PHPYellowTM

Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.

7.5
2005-12-11 CVE-2005-3533 OSH Buffer Overflow vulnerability in Mike Neuman OSH Command Line Argument

Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

7.2
2005-12-08 CVE-2005-4068 IBM Absolute Path Security vulnerability in IBM AIX 5.1/5.2/5.3

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

7.2
2005-12-08 CVE-2005-4089 Microsoft Permissions, Privileges, and Access Controls vulnerability in Microsoft IE 6.0

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."

7.1

77 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-12-09 CVE-2005-4131 Microsoft Unspecified vulnerability in Microsoft Excel

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.

6.8
2005-12-10 CVE-2005-4147 Lyris Technologies INC Information Disclosure vulnerability in Lyris Listmanager TCLHTTPd Service

The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.

6.5
2005-12-10 CVE-2005-4145 Lyris Technologies INC Remote Security vulnerability in Listmanager

The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack.

6.5
2005-12-08 CVE-2005-4093 Checkpoint Permissions, Privileges, and Access Controls vulnerability in Checkpoint Secureclient NG and Vpn-1 Secureclient

Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.

6.5
2005-12-11 CVE-2005-4154 PHP Remote Security vulnerability in PEAR

Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.

5.1
2005-12-07 CVE-2005-3191 Xpdf Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xpdf

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index.

5.1
2005-12-07 CVE-2005-3193 Xpdf Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xpdf

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated.

5.1
2005-12-06 CVE-2005-4030 Quicksilver Forums SQL Injection vulnerability in Quicksilver Forums

SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header.

5.1
2005-12-05 CVE-2005-3996 ZEN Cart SQL Injection vulnerability in Zen-Cart ZEN Cart

SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter.

5.1
2005-12-05 CVE-2005-3995 Sobexsrv Remote Format String vulnerability in Sobexsrv Dosyslog

Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is enabled, allows remote attackers to execute arbitrary code via format string specifiers in file name arguments to OBEX commands.

5.1
2005-12-11 CVE-2005-4173 Efiction Project Input Validation vulnerability in Efiction Project Efiction 1.0/1.1/2.0

eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.

5.0
2005-12-11 CVE-2005-4172 Efiction Project Input Validation vulnerability in Efiction Project Efiction 1.0/1.1/2.0

eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.

5.0
2005-12-11 CVE-2005-4163 Milky Directory Traversal vulnerability in Milky Captcha PHP 0.9

Directory traversal vulnerability in captcha.php in Captcha PHP 0.9 allows remote attackers to read arbitrary files via the _tcf parameter.

5.0
2005-12-11 CVE-2005-4160 Torrential Directory Traversal vulnerability in Torrential

Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument.

5.0
2005-12-10 CVE-2005-4149 Lyris Technologies INC SQL-Injection vulnerability in Listmanager

Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scripts, such as via direct requests, which leaks the installation path, SQL queries, or product code in diagnostic messages.

5.0
2005-12-10 CVE-2005-4148 Lyris Technologies INC Information Disclosure vulnerability in Lyris ListManager Hidden Variable

Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page.

5.0
2005-12-10 CVE-2005-4146 Lyris Technologies INC Information Disclosure vulnerability in Lyris Listmanager TCLHTTPd Service

Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information.

5.0
2005-12-09 CVE-2005-4134 K Meleon Project
Mozilla
Netscape
Buffer Overflow vulnerability in Mozilla Firefox Large History File

Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup.

5.0
2005-12-08 CVE-2005-4095 Docebolms Directory Traversal vulnerability in Docebolms 2.0.4

Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and directories via ".." sequences in the Type parameter in a GetFoldersAndFiles command.

5.0
2005-12-08 CVE-2005-4086 Sugarcrm Remote and Local File Include vulnerability in Sugarcrm Sugar Suite 3.5/4.0Beta

Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the beanFiles array parameter.

5.0
2005-12-08 CVE-2005-3661 Dell Remote Credential Reset vulnerability in Dell TrueMobile 2300

Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration or firmware, via a direct request to apply.cgi with the Page parameter set to adv_password.asp.

5.0
2005-12-08 CVE-2005-4084 Phpbb Styles Remote Security vulnerability in Phpbb Extreme Styles

xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.

5.0
2005-12-08 CVE-2005-4083 Phpbb Styles Directory Traversal vulnerability in Extreme Styles Phpbb Module

Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a ..

5.0
2005-12-08 CVE-2005-4079 Phpmyadmin Unspecified vulnerability in PHPmyadmin 2.7.0Rc1

The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.

5.0
2005-12-08 CVE-2005-4074 Mycfnuke Local File Include vulnerability in Mycfnuke CF Nuke 4.6

Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a ..

5.0
2005-12-07 CVE-2005-4052 E107 Remote Security vulnerability in e107

e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating.

5.0
2005-12-07 CVE-2005-4051 E107 Unspecified vulnerability in E107 0.6174

e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.

5.0
2005-12-06 CVE-2005-4033 ALI Bousahid Unspecified vulnerability in ALI Bousahid Nodezilla

Nodezilla 0.4.13-corno-fulgure does not properly protect the evl_data directory, which could allow them to be shared when they are not protected by PRIVATEDATADIR in nodezilla.ini, which allows remote attackers to obtain sensitive information.

5.0
2005-12-05 CVE-2005-4029 ESI Products Remote Security vulnerability in WebEOC

WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods.

5.0
2005-12-05 CVE-2005-4026 Geeklog Information Disclosure vulnerability in Geeklog (Extended Japanese Package)

search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive information via invalid (1) datestart and (2) dateend parameters, which leaks the web server path in an error message.

5.0
2005-12-05 CVE-2005-4023 Gallery Project Input Validation vulnerability in Gallery

Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors.

5.0
2005-12-05 CVE-2005-4021 Gallery Project Input Validation vulnerability in Gallery

The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

5.0
2005-12-05 CVE-2005-4017 Widget Press property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
5.0
2005-12-05 CVE-2005-4015 PHP WEB Remote Security vulnerability in PHP web Statistik 1.4

PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php.

5.0
2005-12-05 CVE-2005-4013 PHP WEB Information Disclosure vulnerability in PHP web Statistik 1.4

PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file.

5.0
2005-12-07 CVE-2005-4066 Christian Ghisler Cryptographic Issues vulnerability in Christian Ghisler Total Commander 6.53

Total Commander 6.53 uses weak encryption to store FTP usernames and passwords in WCX_FTP.INI, which allows local users to decrypt the passwords and gain access to FTP servers, as possibly demonstrated by the W32.Gudeb worm.

4.9
2005-12-11 CVE-2005-4158 Todd Miller Unspecified vulnerability in Todd Miller Sudo

Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script.

4.6
2005-12-08 CVE-2005-4082 QNX Local DHCP.Client vulnerability in QNX 4.25

The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.

4.6
2005-12-08 CVE-2005-4077 Daniel Stenberg Numeric Errors vulnerability in Daniel Stenberg Curl

Multiple off-by-one errors in the cURL library (libcurl) 7.11.2 through 7.15.0 allow local users to trigger a buffer overflow and cause a denial of service or bypass PHP security restrictions via certain URLs that (1) are malformed in a way that prevents a terminating null byte from being added to either a hostname or path buffer, or (2) contain a "?" separator in the hostname portion, which causes a "/" to be prepended to the resulting string.

4.6
2005-12-08 CVE-2005-4076 Appfluent Technology Buffer Overflow vulnerability in Appfluent Technology Database IDS 2.0

Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable.

4.6
2005-12-08 CVE-2005-4069 Sunncomm Permissions, Privileges, and Access Controls vulnerability in Sunncomm Mediamax DRM 5.0.21.0

SunnComm MediaMax DRM 5.0.21.0, as used by Sony BMG, assigns insecure Everyone/Full Control permissions to the "SunnComm Shared" directory, which allows local users to gain privileges by modifying programs installed in that directory, such as MMX.exe.

4.6
2005-12-11 CVE-2005-4167 Efiction Project Input Validation vulnerability in Efiction 1.0/1.1

Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.

4.3
2005-12-11 CVE-2005-4166 Duware Cross-Site Scripting vulnerability in DuWare DuPortalPro Password.ASP

Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter.

4.3
2005-12-11 CVE-2005-4162 Acme Labs Cross-Site Scripting vulnerability in Acme Labs Perlcal 2.99/2.99.20/2.99.30

Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.

4.3
2005-12-11 CVE-2005-4161 Milliscripts Cross-Site Scripting vulnerability in Milliscripts 1.4

** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject arbitrary web script or HTML via the domainname parameter to register.php, and other unspecified vectors.

4.3
2005-12-10 CVE-2005-4150 Broadcom Unspecified vulnerability in Broadcom Cleverpath Portal 4.7

Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors.

4.3
2005-12-09 CVE-2005-4138 Thwboard Input Validation vulnerability in ThWboard

Multiple cross-site scripting (XSS) vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) Wohnort and (2) Beruf fields in editprofile.php, (3) user parameter array in v_profile.php, and (4) the action parameter in misc.php.

4.3
2005-12-09 CVE-2005-4136 FAD Solutions Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2

Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter.

4.3
2005-12-08 CVE-2005-4091 1 Script Cross-Site Scripting vulnerability in 1-Script 1-Search 1.8

Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

4.3
2005-12-08 CVE-2005-3665 Phpmyadmin Cross-Site Scripting vulnerability in PHPMyAdmin

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation.

4.3
2005-12-08 CVE-2005-4080 Horde Unspecified vulnerability in Horde IMP

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

4.3
2005-12-08 CVE-2005-4078 Ideal Science Cross-Site Scripting vulnerability in Ideal Bb.Net

Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p parameters in topics.aspx, (4) boardID parameter in categoryindex.aspx, (5) postID parameter in posts.aspx, (6) catID parameter in forums.aspx, and (7) memberID parameter in member.aspx.

4.3
2005-12-08 CVE-2005-4075 Mycfnuke Cross-Site Scripting vulnerability in Mycfnuke CF Nuke 3.0A/4.0/4.5

Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector.

4.3
2005-12-08 CVE-2005-4072 Cfmagic Products Input Validation vulnerability in CFMagic

Cross-site scripting (XSS) vulnerability in CFMagic Magic Forum Personal 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the Words parameter in search_forums.cfm, as used in the "Search For:" field.

4.3
2005-12-07 CVE-2005-4063 Netauctionhelp Cross-Site Scripting vulnerability in NetauctionHelp

Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.

4.3
2005-12-07 CVE-2005-4062 Xcent Cross-Site Scripting vulnerability in XcClassified CPSearch.ASP

Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.

4.3
2005-12-07 CVE-2005-4061 Xcent Cross-Site Scripting vulnerability in XcPhotoAlbum PASearch.ASP

Cross-site scripting (XSS) vulnerability in PASearch.asp in XcPhotoAlbum 1.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.

4.3
2005-12-07 CVE-2005-4060 Rainworx Cross-Site Scripting vulnerability in Rainworx Rwauction PRO 4.0/5.0

Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.

4.3
2005-12-07 CVE-2005-4057 Jonathan Beckett Unspecified vulnerability in Jonathan Beckett Pluggedout Nexus 0.1

Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters.

4.3
2005-12-07 CVE-2005-4053 Cowiki Cross-Site Scripting vulnerability in Cowiki 0.3.4

Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html.

4.3
2005-12-07 CVE-2005-4047 Iisworks Cross-Site Scripting vulnerability in Iisworks Aspknowledgebase 2.0

Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter.

4.3
2005-12-06 CVE-2005-4044 MR CGI GUY Cross-Site Scripting vulnerability in Amazon Search Directory

Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter.

4.3
2005-12-06 CVE-2005-4042 MR CGI GUY Cross-Site Scripting vulnerability in MR. CGI GUY Warm Links 1.0.0

Cross-site scripting (XSS) vulnerability in Warm Links 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to search.cgi.

4.3
2005-12-06 CVE-2005-4041 MR CGI GUY Software Search.CGI Cross-Site Scripting vulnerability in Mr CGI Guy

Cross-site scripting (XSS) vulnerability in search.cgi in MR CGI Guy Hot Links SQL 3.1.x and Hot Links Pro 3.1.x allows remote attackers to inject arbitrary web script or HTML via the query string.

4.3
2005-12-06 CVE-2005-4036 Web4Future Cross-Site Scripting vulnerability in Web4Future Keyword Frequency Counter 1.0

Cross-site scripting (XSS) vulnerability in index.cgi in Web4Future KeyWord Frequency Counter 1.0 allows remote attackers to inject arbitrary web script or HTML via the "remote URL."

4.3
2005-12-06 CVE-2005-4032 Hotcgiscripts Cross-Site Scripting vulnerability in Easy Search System Search.cgi

Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.

4.3
2005-12-05 CVE-2005-4028 Amember Cross-Site Scripting vulnerability in Amember

Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login parameter to member.php.

4.3
2005-12-05 CVE-2005-4024 Interspire Cross-Site Scripting vulnerability in Fastfind 2004/2005

Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

4.3
2005-12-05 CVE-2005-4022 Gallery Project Input Validation vulnerability in Gallery

Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

4.3
2005-12-05 CVE-2005-4012 PHP WEB Unspecified vulnerability in PHP web Statistik 1.4

Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary web script or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP referer to pixel.php.

4.3
2005-12-05 CVE-2005-4004 Infinetsoftware Cross-Site Scripting vulnerability in InfinetSoftware MyTemplateSite Search.ASP

Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.

4.3
2005-12-05 CVE-2005-4000 Sitebeater Cross-Site Scripting vulnerability in SiteBeater News Archive.ASP

Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter.

4.3
2005-12-05 CVE-2005-3999 Sitebeater Cross-Site Scripting vulnerability in Sitebeater MP3 Catalog 2.0.3

Cross-site scripting (XSS) vulnerability in Search.asp in SiteBeater MP3 Catalog 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

4.3
2005-12-05 CVE-2005-3998 Solupress Cross-Site Scripting vulnerability in Solupress News Search.ASP

Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

4.3
2005-12-07 CVE-2005-4046 SUN Man In The Middle vulnerability in SUN products

Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers to conduct man-in-the-middle (MITM) attacks and "compromise data privacy."

4.0
2005-12-07 CVE-2005-2923 Ipswitch Improper Input Validation vulnerability in Ipswitch Imail Server and Ipswitch Collaboration Suite

The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory.

4.0
2005-12-05 CVE-2005-4002 ESI Products Remote Security vulnerability in WebEOC

WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.

4.0

5 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2005-12-05 CVE-2005-3997 ZEN Cart Information Disclosure vulnerability in Zen Cart

Zen Cart 1.2.6d and earlier, under certain PHP configurations, allows remote attackers to obtain sensitive information via direct requests to files in the admin/includes directory, including (1) graphs/banner_daily.php, (2) graphs/banner_infobox.php, (3) graphs/banner_yearly.php, (4) graphs/banner_monthly.php, (5) application_bottom.php, (6) attributes_preview.php, (7) modules/category_product_listing.php, (8) modules/copy_to_confirm.php, (9) modules/delete_product_confirm.php, and (10) modules/move_product_confirm.php, which leaks the web server path in the resulting error message.

2.6
2005-12-11 CVE-2005-4176 Award AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.
2.1
2005-12-11 CVE-2005-4175 Insyde Unspecified vulnerability in Insyde Bios V190

Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory.

2.1
2005-12-10 CVE-2005-4151 PGP Unspecified vulnerability in PGP Desktop 8.0/9.0

The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.

2.1
2005-12-09 CVE-2005-4133 SUN Unspecified vulnerability in SUN Solaris 10.0

Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files.

2.1