Weekly Vulnerabilities Reports > December 5 to 11, 2005
Overview
150 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 69 high severity vulnerabilities. This weekly summary report vulnerabilities in 124 products from 103 vendors including Efiction Project, Web4Future, Lyris Technologies INC, PHP WEB, and SUN. Vulnerabilities are notably categorized as "SQL Injection", "Improper Restriction of Operations within the Bounds of a Memory Buffer", "Permissions, Privileges, and Access Controls", "Numeric Errors", and "Cross-site Scripting".
- 138 reported vulnerabilities are remotely exploitables.
- 8 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 146 reported vulnerabilities are exploitable by an anonymous user.
- Efiction Project has the most reported vulnerabilities, with 8 reported vulnerabilities.
- HP has the most reported critical vulnerabilities, with 1 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
2 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-12-08 | CVE-2005-4090 | HP | IPSec Unauthorized Remote Access vulnerability in HP-UX Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact. | 10.0 |
2005-12-11 | CVE-2005-4156 | Mambo | Denial-Of-Service vulnerability in Mambo Open Source 4.5 Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character. | 9.4 |
69 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-12-11 | CVE-2005-4153 | GNU | Denial Of Service vulnerability in GNU Mailman 2.1.4/2.1.5/2.1.6 Mailman 2.1.4 through 2.1.6 allows remote attackers to cause a denial of service via a message that causes the server to "fail with an Overflow on bad date data in a processed message," a different vulnerability than CVE-2005-3573. | 7.8 |
2005-12-11 | CVE-2005-4152 | Soti | Unspecified vulnerability in Soti Pocket Controller-Professional 5.0 Soti Pocket Controller-Professional 5.0 allows remote attackers to turn off, reboot, or hard reset a PDA via a series of initialization, command, and reset packets sent to port 5492. | 7.8 |
2005-12-06 | CVE-2005-4039 | Web4Future | Directory Traversal vulnerability in Web4Future Portal Solutions Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter. | 7.8 |
2005-12-05 | CVE-2005-4014 | PHP WEB | Denial-Of-Service vulnerability in PHP web Statistik 1.4 stat.php in PHP Web Statistik 1.4 allows remote attackers to cause a denial of service (CPU consumption) via a large lastnumber value. | 7.8 |
2005-12-05 | CVE-2005-3993 | Mailenable | Denial-Of-Service vulnerability in MailEnable Enterprise Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands. | 7.8 |
2005-12-11 | CVE-2005-4174 | Efiction Project | Input Validation vulnerability in eFiction eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. | 7.5 |
2005-12-11 | CVE-2005-4171 | Efiction Project | Input Validation vulnerability in Efiction Project Efiction 1.1 The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file. | 7.5 |
2005-12-11 | CVE-2005-4170 | Efiction Project | Input Validation vulnerability in Efiction Project Efiction 1.1 SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php. | 7.5 |
2005-12-11 | CVE-2005-4169 | Efiction Project | Input Validation vulnerability in Efiction Project Efiction 1.0 Multiple SQL injection vulnerabilities in eFiction 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) let parameter in a viewlist action to authors.php and (2) sid parameter to viewstory.php. | 7.5 |
2005-12-11 | CVE-2005-4168 | Efiction Project | Input Validation vulnerability in Efiction Project Efiction 1.0/1.1/2.0 Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username. | 7.5 |
2005-12-11 | CVE-2005-4165 | ASP DEV | Cross-Site Scripting vulnerability in ASP-DEV XM Forum Forum.ASP Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the "Search For" field in search.asp. | 7.5 |
2005-12-11 | CVE-2005-4164 | Widgetmonkey | SQL-Injection vulnerability in Widgetmonkey PHP-Addressbook 1.2 SQL injection vulnerability in view.php in PHP-addressbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2005-12-11 | CVE-2005-4157 | Kerio | Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account that has been disabled. | 7.5 |
2005-12-11 | CVE-2005-4155 | Adaptive Technology Resource Centre | Unspecified vulnerability in Adaptive Technology Resource Centre Atutor 1.5.1Pl2 registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address that ends in a NULL character, which bypasses the PHP regular expression check. | 7.5 |
2005-12-11 | CVE-2005-3532 | Double Precision Incorporated | Unspecified vulnerability in Double Precision Incorporated Courier Mail Server authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled. | 7.5 |
2005-12-10 | CVE-2005-4144 | Lyris | SQL Injection vulnerability in Lyris ListManager Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace. | 7.5 |
2005-12-10 | CVE-2005-4143 | Lyris | SQL Injection vulnerability in Lyris ListManager SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL. | 7.5 |
2005-12-10 | CVE-2005-4142 | Lyris Technologies INC | Unspecified vulnerability in Lyris Technologies INC Listmanager The web interface for subscribing new users in Lyris ListManager 5.0 through 8.8b, in combination with a line wrap feature, allows remote attackers to execute arbitrary list administration commands via LFCR (%0A%0D) sequences in the pw parameter. | 7.5 |
2005-12-09 | CVE-2005-4141 | Aspmforum | SQL Injection vulnerability in ASPMForum Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp. | 7.5 |
2005-12-09 | CVE-2005-4140 | Website Baker | SQL Injection vulnerability in Website Baker 2.5.2/2.6 SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter, as used by the user field. | 7.5 |
2005-12-09 | CVE-2005-4139 | Thwboard | Input Validation vulnerability in Thwboard Beta 2.8 Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php. | 7.5 |
2005-12-09 | CVE-2005-4137 | FAD Solutions | Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2 SQL injection vulnerability in viewinvoice.php in DRZES HMS 3.2 allows remote attackers to execute arbitrary SQL commands via the invoiceID parameter. | 7.5 |
2005-12-09 | CVE-2005-4135 | Simplemedia | Remote Arbitrary Command Execution vulnerability in Simplebbs 1.0.6/1.0.7/1.1 Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php. | 7.5 |
2005-12-09 | CVE-2005-4132 | Contenido | Remote Command Execution vulnerability in Contenido Contendio 4.5.2Alpha/4.5.6Beta/4.6.0 Unspecified "security leak" vulnerability in Contenido before 4.6.4, when register_globals is on and allow_url_fopen is true, has unspecified impact and attack vectors. | 7.5 |
2005-12-09 | CVE-2005-4130 | Realnetworks | Unspecified vulnerability in Realnetworks Realplayer ** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. | 7.5 |
2005-12-09 | CVE-2005-4126 | Realnetworks | Remote Code Execution vulnerability in Real Networks RealPlayer ** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. | 7.5 |
2005-12-08 | CVE-2005-4094 | Docebolms | Unspecified vulnerability in Docebolms 2.0.4 connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to execute arbitrary PHP by using the FileUpload command to upload a file that appears to be an image but contains PHP script. | 7.5 |
2005-12-08 | CVE-2005-4092 | Apple | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Itunes and Quicktime Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and possibly other vectors involving media files. | 7.5 |
2005-12-08 | CVE-2005-4088 | W2B | SQL Injection vulnerability in PHPForumPro SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and (2) day parameters. | 7.5 |
2005-12-08 | CVE-2005-4087 | Sugarcrm | Remote and Local File Include vulnerability in Sugarcrm Sugar Suite 3.5/4.0Beta PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter. | 7.5 |
2005-12-08 | CVE-2005-4081 | Alisveristr | Unspecified vulnerability in Alisveristr E-Commerce Multiple SQL injection vulnerabilities in Alisveristr E-commerce allow remote attackers to bypass authentication and possibly execute arbitrary SQL commands via the username and password parameters in (1) the user login and (2) administrator login pages. | 7.5 |
2005-12-08 | CVE-2005-4073 | Cfmagic | SQL Injection vulnerability in Cfmagic Magic List PRO SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter. | 7.5 |
2005-12-08 | CVE-2005-4071 | Cfmagic | SQL Injection vulnerability in Cfmagic Magic Forum Personal Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ForumID parameter in view_forum.cfm, and (2) ForumID, (3) Thread, and (4) ThreadID parameters in view_thread.cfm. | 7.5 |
2005-12-08 | CVE-2005-3192 | Xpdf | Buffer Errors vulnerability in Xpdf 3.0.1 Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field. | 7.5 |
2005-12-07 | CVE-2005-4065 | Edgewall Software | SQL Injection vulnerability in Edgewall Software Trac Search Module SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 7.5 |
2005-12-07 | CVE-2005-4064 | Alan Ward | SQL Injection vulnerability in Alan Ward A-Faq 1.0 Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) faqid parameter to faqDspItem.asp and (2) catcode parameter to faqDsp.asp. | 7.5 |
2005-12-07 | CVE-2005-4059 | Locazo | Unspecified vulnerability in Locazo Locazolist SQL injection vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to execute arbitrary SQL commands via the q parameter. | 7.5 |
2005-12-07 | CVE-2005-4058 | Saralblog | SQL Injection vulnerability in Saralblog 1/1Beta SQL injection vulnerability in saralblog 1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to viewprofile.php. | 7.5 |
2005-12-07 | CVE-2005-4056 | Jonathan Beckett | Unspecified vulnerability in Jonathan Beckett Pluggedout Nexus 0.1 SQL injection vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) Location, (2) Last Name, and (3) First Name parameters. | 7.5 |
2005-12-07 | CVE-2005-4055 | Cars Portal | SQL Injection vulnerability in Cars Portal SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters. | 7.5 |
2005-12-07 | CVE-2005-4054 | Pluggedout | SQL Injection vulnerability in Pluggedout Blog 1.9.5 SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter. | 7.5 |
2005-12-07 | CVE-2005-4050 | Multi Tech Systems | Remote Buffer Overflow vulnerability in MultiTech MultiVOIP INVITE Buffer overflow in multiple Multi-Tech Systems MultiVOIP devices with firmware before x.08 allows remote attackers to execute arbitrary code via a long INVITE field in a Session Initiation Protocol (SIP) packet. | 7.5 |
2005-12-07 | CVE-2005-4049 | Netart Media | Unspecified vulnerability in Netart Media Blog System 1.2 Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php. | 7.5 |
2005-12-07 | CVE-2005-4048 | Ffmpeg | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ffmpeg Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary commands via small PNG images with palettes. | 7.5 |
2005-12-07 | CVE-2005-4045 | SUN | Unspecified vulnerability in SUN Java Communications Services Delegated Administrator 6 Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif. | 7.5 |
2005-12-07 | CVE-2005-2931 | Ipswitch | Remote Format String vulnerability in Ipswitch Imail Server and Ipswitch Collaboration Suite Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands. | 7.5 |
2005-12-06 | CVE-2005-4043 | Hobosworld | SQL Injection vulnerability in Hobosworld HobSR SQL injection vulnerability in view.php in Hobosworld HobSR 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) arrange and (2) p parameters. | 7.5 |
2005-12-06 | CVE-2005-4040 | Tawbaware | SQL Injection vulnerability in Tawbaware Filelister SQL injection vulnerability in FileLister 0.51 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameters, possibly the searchwhat parameter to definesearch.jsp. | 7.5 |
2005-12-06 | CVE-2005-4038 | Web4Future | SQL Injection vulnerability in Web4Future Portal Solutions Comentarii.PHP SQL injection vulnerability in comentarii.php in Web4Future Portal Solutions News Portal allows remote attackers to execute arbitrary SQL commands via the idp parameter. | 7.5 |
2005-12-06 | CVE-2005-4037 | Web4Future | SQL Injection vulnerability in Web4Future Affiliate Manager PRO Functions.PHP SQL injection vulnerability in functions.php in Web4Future Affiliate Manager PRO 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. | 7.5 |
2005-12-06 | CVE-2005-4035 | Web4Future | SQL Injection vulnerability in Web4Future eCommerce Enterprise Edition Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php. | 7.5 |
2005-12-06 | CVE-2005-4034 | Web4Future | SQL Injection vulnerability in Web4Future Edating Professional 5 Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php. | 7.5 |
2005-12-06 | CVE-2005-4031 | Mediawiki | Remote Code Execution vulnerability in MediaWiki User Language Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function. | 7.5 |
2005-12-05 | CVE-2005-4027 | Simplemedia | SQL Injection vulnerability in Simplemedia Simplebbs 1.1 SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters. | 7.5 |
2005-12-05 | CVE-2005-4025 | Help Desk Reloaded | Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. | 7.5 |
2005-12-05 | CVE-2005-4020 | Widget Press | SQL-Injection vulnerability in Widget Imprint SQL injection vulnerability in create.php in Widget Imprint 1.0.26 and earlier allows remote attackers to execute arbitrary SQL commands via the product_id parameter. | 7.5 |
2005-12-05 | CVE-2005-4019 | Relative Real Estate Systems | SQL Injection vulnerability in Relative Real Estate Systems SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter. | 7.5 |
2005-12-05 | CVE-2005-4018 | Landshop | SQL Injection vulnerability in SAMEDIA Landshop SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters. | 7.5 |
2005-12-05 | CVE-2005-4016 | Widget Press | SQL Injection vulnerability in Widget Press Widget Property 1.1.19 SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php. | 7.5 |
2005-12-05 | CVE-2005-4011 | Codewalkers | SQL Injection vulnerability in Codewalkers Ltwcalendar SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2005-12-05 | CVE-2005-4010 | Sensation Designs | SQL Injection vulnerability in KBase Express SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php. | 7.5 |
2005-12-05 | CVE-2005-4009 | PHP Lite | SQL-Injection vulnerability in PHP Lite Calendar Express 2.0/2.2 Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php. | 7.5 |
2005-12-05 | CVE-2005-4008 | JAX Calendar | SQL Injection vulnerability in JAX Calendar JAX Calendar 1.34 SQL injection vulnerability in jax_calendar.php in Jax Calendar 1.34 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter, and possibly the (2) Y and (3) m parameters. | 7.5 |
2005-12-05 | CVE-2005-4005 | PHP Fusion | SQL Injection vulnerability in PHP Fusion PHP Fusion 6.00.109 SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to obtain path information and possibly execute arbitrary SQL commands via the srch_text parameter in a Search and Sort option to messages.php. | 7.5 |
2005-12-05 | CVE-2005-4003 | Asps | Cross-Site Scripting vulnerability in Absolute Shopping Package Solutions Shopping Cart 2.1/2.9D Multiple SQL injection vulnerabilities in Absolute Shopping Package Solutions (ASPS) Shopping Cart Professional 2.9d and earlier, and Lite 2.1 and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) srch_product_name parameter to adv_search.asp and (2) b_search parameter to bsearch.asp. | 7.5 |
2005-12-05 | CVE-2005-4001 | Phpyellow | SQL Injection vulnerability in PHPYellowTM Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php. | 7.5 |
2005-12-11 | CVE-2005-3533 | OSH | Buffer Overflow vulnerability in Mike Neuman OSH Command Line Argument Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename. | 7.2 |
2005-12-08 | CVE-2005-4068 | IBM | Absolute Path Security vulnerability in IBM AIX 5.1/5.2/5.3 Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors. | 7.2 |
2005-12-08 | CVE-2005-4089 | Microsoft | Permissions, Privileges, and Access Controls vulnerability in Microsoft IE and Internet Explorer Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability." | 7.1 |
74 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-12-10 | CVE-2005-4147 | Lyris Technologies INC | Information Disclosure vulnerability in Lyris Listmanager TCLHTTPd Service The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters. | 6.5 |
2005-12-10 | CVE-2005-4145 | Lyris Technologies INC | Remote Security vulnerability in Listmanager The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search space ("lyris" and up to 5 digits, possibly from the process ID), which allows remote attackers to gain access via a brute force attack. | 6.5 |
2005-12-11 | CVE-2005-4154 | PHP | Remote Security vulnerability in PEAR Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded. | 5.1 |
2005-12-07 | CVE-2005-3191 | Xpdf | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xpdf Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a) Poppler, (b) teTeX, (c) KDE kpdf, (d) pdftohtml, (e) KOffice KWord, (f) CUPS, and (g) libextractor allow user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with an out-of-range number of components (numComps), which is used as an array index. | 5.1 |
2005-12-07 | CVE-2005-3193 | Xpdf | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Xpdf Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and (5) libextractor allows user-assisted attackers to cause a denial of service (heap corruption) and possibly execute arbitrary code via a crafted PDF file with large size values that cause insufficient memory to be allocated. | 5.1 |
2005-12-06 | CVE-2005-4030 | Quicksilver Forums | SQL Injection vulnerability in Quicksilver Forums SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header. | 5.1 |
2005-12-05 | CVE-2005-3996 | ZEN Cart | SQL Injection vulnerability in Zen-Cart ZEN Cart SQL injection vulnerability in admin/password_forgotten.php in Zen Cart 1.2.6d and earlier allows remote attackers to execute arbitrary SQL commands via the admin_email parameter. | 5.1 |
2005-12-05 | CVE-2005-3995 | Sobexsrv | Remote Format String vulnerability in Sobexsrv Dosyslog Format string vulnerability in the dosyslog function in the OBEX server (obexsrv.c) for Sobexsrv before 1.0.0-pre4, when the syslog (-S) function is enabled, allows remote attackers to execute arbitrary code via format string specifiers in file name arguments to OBEX commands. | 5.1 |
2005-12-11 | CVE-2005-4173 | Efiction Project | Input Validation vulnerability in Efiction Project Efiction 1.0/1.1/2.0 eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function. | 5.0 |
2005-12-11 | CVE-2005-4172 | Efiction Project | Input Validation vulnerability in Efiction Project Efiction 1.0/1.1/2.0 eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message. | 5.0 |
2005-12-11 | CVE-2005-4163 | Milky | Directory Traversal vulnerability in Milky Captcha PHP 0.9 Directory traversal vulnerability in captcha.php in Captcha PHP 0.9 allows remote attackers to read arbitrary files via the _tcf parameter. | 5.0 |
2005-12-11 | CVE-2005-4160 | Torrential | Directory Traversal vulnerability in Torrential Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via "../" sequences in the query string argument. | 5.0 |
2005-12-10 | CVE-2005-4149 | Lyris Technologies INC | SQL-Injection vulnerability in Listmanager Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scripts, such as via direct requests, which leaks the installation path, SQL queries, or product code in diagnostic messages. | 5.0 |
2005-12-10 | CVE-2005-4148 | Lyris Technologies INC | Information Disclosure vulnerability in Lyris ListManager Hidden Variable Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable, which allows remote attackers to obtain information such as the installation path by requesting a non-existent page and reading the env variable from the resulting error message page. | 5.0 |
2005-12-10 | CVE-2005-4146 | Lyris Technologies INC | Information Disclosure vulnerability in Lyris Listmanager TCLHTTPd Service Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd status module, which provides sensitive server configuration information. | 5.0 |
2005-12-09 | CVE-2005-4134 | K Meleon Project Mozilla Netscape | Buffer Overflow vulnerability in Mozilla Firefox Large History File Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. | 5.0 |
2005-12-08 | CVE-2005-4095 | Docebolms | Directory Traversal vulnerability in Docebolms 2.0.4 Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and directories via ".." sequences in the Type parameter in a GetFoldersAndFiles command. | 5.0 |
2005-12-08 | CVE-2005-4086 | Sugarcrm | Remote and Local File Include vulnerability in Sugarcrm Sugar Suite 3.5/4.0Beta Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the beanFiles array parameter. | 5.0 |
2005-12-08 | CVE-2005-3661 | Dell | Remote Credential Reset vulnerability in Dell TrueMobile 2300 Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration or firmware, via a direct request to apply.cgi with the Page parameter set to adv_password.asp. | 5.0 |
2005-12-08 | CVE-2005-4084 | Phpbb Styles | Remote Security vulnerability in Phpbb Extreme Styles xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter. | 5.0 |
2005-12-08 | CVE-2005-4083 | Phpbb Styles | Directory Traversal vulnerability in Extreme Styles Phpbb Module Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. | 5.0 |
2005-12-08 | CVE-2005-4079 | Phpmyadmin | Unspecified vulnerability in PHPmyadmin 2.7.0Rc1 The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables. | 5.0 |
2005-12-08 | CVE-2005-4074 | Mycfnuke | Local File Include vulnerability in Mycfnuke CF Nuke 4.6 Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a .. | 5.0 |
2005-12-07 | CVE-2005-4052 | E107 | Remote Security vulnerability in e107 e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating. | 5.0 |
2005-12-07 | CVE-2005-4051 | E107 | Unspecified vulnerability in E107 0.6174 e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php. | 5.0 |
2005-12-06 | CVE-2005-4033 | ALI Bousahid | Unspecified vulnerability in ALI Bousahid Nodezilla Nodezilla 0.4.13-corno-fulgure does not properly protect the evl_data directory, which could allow them to be shared when they are not protected by PRIVATEDATADIR in nodezilla.ini, which allows remote attackers to obtain sensitive information. | 5.0 |
2005-12-05 | CVE-2005-4029 | ESI Products | Remote Security vulnerability in WebEOC WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods. | 5.0 |
2005-12-05 | CVE-2005-4026 | Geeklog | Information Disclosure vulnerability in Geeklog (Extended Japanese Package) search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive information via invalid (1) datestart and (2) dateend parameters, which leaks the web server path in an error message. | 5.0 |
2005-12-05 | CVE-2005-4023 | Gallery Project | Input Validation vulnerability in Gallery Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors. | 5.0 |
2005-12-05 | CVE-2005-4021 | Gallery Project | Input Validation vulnerability in Gallery The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information. | 5.0 |
2005-12-05 | CVE-2005-4017 | Widget Press | property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message. | 5.0 |
2005-12-05 | CVE-2005-4015 | PHP WEB | Remote Security vulnerability in PHP web Statistik 1.4 PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php. | 5.0 |
2005-12-05 | CVE-2005-4013 | PHP WEB | Information Disclosure vulnerability in PHP web Statistik 1.4 PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file. | 5.0 |
2005-12-07 | CVE-2005-4066 | Christian Ghisler | Cryptographic Issues vulnerability in Christian Ghisler Total Commander 6.53 Total Commander 6.53 uses weak encryption to store FTP usernames and passwords in WCX_FTP.INI, which allows local users to decrypt the passwords and gain access to FTP servers, as possibly demonstrated by the W32.Gudeb worm. | 4.9 |
2005-12-11 | CVE-2005-4158 | Todd Miller | Unspecified vulnerability in Todd Miller Sudo Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT environment variables, which allows limited local users to cause a Perl script to include and execute arbitrary library files that have the same name as library files that are included by the script. | 4.6 |
2005-12-08 | CVE-2005-4082 | QNX | Local DHCP.Client vulnerability in QNX 4.25 The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks. | 4.6 |
2005-12-08 | CVE-2005-4077 | Daniel Stenberg | Numeric Errors vulnerability in Daniel Stenberg Curl Multiple off-by-one errors in the cURL library (libcurl) 7.11.2 through 7.15.0 allow local users to trigger a buffer overflow and cause a denial of service or bypass PHP security restrictions via certain URLs that (1) are malformed in a way that prevents a terminating null byte from being added to either a hostname or path buffer, or (2) contain a "?" separator in the hostname portion, which causes a "/" to be prepended to the resulting string. | 4.6 |
2005-12-08 | CVE-2005-4076 | Appfluent Technology | Buffer Overflow vulnerability in Appfluent Technology Database IDS 2.0 Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable. | 4.6 |
2005-12-08 | CVE-2005-4069 | Sunncomm | Permissions, Privileges, and Access Controls vulnerability in Sunncomm Mediamax DRM 5.0.21.0 SunnComm MediaMax DRM 5.0.21.0, as used by Sony BMG, assigns insecure Everyone/Full Control permissions to the "SunnComm Shared" directory, which allows local users to gain privileges by modifying programs installed in that directory, such as MMX.exe. | 4.6 |
2005-12-11 | CVE-2005-4167 | Efiction Project | Input Validation vulnerability in Efiction 1.0/1.1 Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php. | 4.3 |
2005-12-11 | CVE-2005-4166 | Duware | Cross-Site Scripting vulnerability in DuWare DuPortalPro Password.ASP Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter. | 4.3 |
2005-12-11 | CVE-2005-4162 | Acme Labs | Cross-Site Scripting vulnerability in Acme Labs Perlcal 2.99/2.99.20/2.99.30 Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter. | 4.3 |
2005-12-10 | CVE-2005-4150 | Broadcom | Unspecified vulnerability in Broadcom Cleverpath Portal 4.7 Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors. | 4.3 |
2005-12-09 | CVE-2005-4138 | Thwboard | Input Validation vulnerability in ThWboard Multiple cross-site scripting (XSS) vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) Wohnort and (2) Beruf fields in editprofile.php, (3) user parameter array in v_profile.php, and (4) the action parameter in misc.php. | 4.3 |
2005-12-09 | CVE-2005-4136 | FAD Solutions | Cross-Site Scripting vulnerability in FAD Solutions Drzes HMS 3.2 Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via the customerEmailAddress parameter. | 4.3 |
2005-12-08 | CVE-2005-4091 | 1 Script | Cross-Site Scripting vulnerability in 1-Script 1-Search 1.8 Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 4.3 |
2005-12-08 | CVE-2005-3665 | Phpmyadmin | Cross-Site Scripting vulnerability in PHPMyAdmin Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation. | 4.3 |
2005-12-08 | CVE-2005-4080 | Horde | Unspecified vulnerability in Horde IMP Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters. | 4.3 |
2005-12-08 | CVE-2005-4078 | Ideal Science | Cross-Site Scripting vulnerability in Ideal Bb.Net Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p parameters in topics.aspx, (4) boardID parameter in categoryindex.aspx, (5) postID parameter in posts.aspx, (6) catID parameter in forums.aspx, and (7) memberID parameter in member.aspx. | 4.3 |
2005-12-08 | CVE-2005-4075 | Mycfnuke | Cross-Site Scripting vulnerability in Mycfnuke CF Nuke 3.0A/4.0/4.5 Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) newsid parameter in the news sector, and (3) cat parameter in the links sector. | 4.3 |
2005-12-08 | CVE-2005-4072 | Cfmagic | Products Input Validation vulnerability in CFMagic Cross-site scripting (XSS) vulnerability in CFMagic Magic Forum Personal 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the Words parameter in search_forums.cfm, as used in the "Search For:" field. | 4.3 |
2005-12-07 | CVE-2005-4063 | Netauctionhelp | Cross-Site Scripting vulnerability in NetauctionHelp Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp. | 4.3 |
2005-12-07 | CVE-2005-4062 | Xcent | Cross-Site Scripting vulnerability in XcClassified CPSearch.ASP Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters. | 4.3 |
2005-12-07 | CVE-2005-4061 | Xcent | Cross-Site Scripting vulnerability in XcPhotoAlbum PASearch.ASP Cross-site scripting (XSS) vulnerability in PASearch.asp in XcPhotoAlbum 1.x allows remote attackers to inject arbitrary web script or HTML via the search parameters. | 4.3 |
2005-12-07 | CVE-2005-4060 | Rainworx | Cross-Site Scripting vulnerability in Rainworx Rwauction PRO 4.0/5.0 Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. | 4.3 |
2005-12-07 | CVE-2005-4057 | Jonathan Beckett | Unspecified vulnerability in Jonathan Beckett Pluggedout Nexus 0.1 Cross-site scripting (XSS) vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Location, (2) Last Name, and (3) First Name parameters. | 4.3 |
2005-12-07 | CVE-2005-4053 | Cowiki | Cross-Site Scripting vulnerability in Cowiki 0.3.4 Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html. | 4.3 |
2005-12-07 | CVE-2005-4047 | Iisworks | Cross-Site Scripting vulnerability in Iisworks Aspknowledgebase 2.0 Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter. | 4.3 |
2005-12-06 | CVE-2005-4044 | MR CGI GUY | Cross-Site Scripting vulnerability in Amazon Search Directory Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter. | 4.3 |
2005-12-06 | CVE-2005-4042 | MR CGI GUY | Cross-Site Scripting vulnerability in MR. CGI GUY Warm Links 1.0.0 Cross-site scripting (XSS) vulnerability in Warm Links 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to search.cgi. | 4.3 |
2005-12-06 | CVE-2005-4041 | MR CGI GUY | Software Search.CGI Cross-Site Scripting vulnerability in Mr CGI Guy Cross-site scripting (XSS) vulnerability in search.cgi in MR CGI Guy Hot Links SQL 3.1.x and Hot Links Pro 3.1.x allows remote attackers to inject arbitrary web script or HTML via the query string. | 4.3 |
2005-12-06 | CVE-2005-4036 | Web4Future | Cross-Site Scripting vulnerability in Web4Future Keyword Frequency Counter 1.0 Cross-site scripting (XSS) vulnerability in index.cgi in Web4Future KeyWord Frequency Counter 1.0 allows remote attackers to inject arbitrary web script or HTML via the "remote URL." | 4.3 |
2005-12-06 | CVE-2005-4032 | Hotcgiscripts | Cross-Site Scripting vulnerability in Easy Search System Search.cgi Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 4.3 |
2005-12-05 | CVE-2005-4028 | Amember | Cross-Site Scripting vulnerability in Amember Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login parameter to member.php. | 4.3 |
2005-12-05 | CVE-2005-4024 | Interspire | Cross-Site Scripting vulnerability in Fastfind 2004/2005 Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | 4.3 |
2005-12-05 | CVE-2005-4022 | Gallery Project | Input Validation vulnerability in Gallery Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | 4.3 |
2005-12-05 | CVE-2005-4012 | PHP WEB | Unspecified vulnerability in PHP web Statistik 1.4 Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary web script or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP referer to pixel.php. | 4.3 |
2005-12-05 | CVE-2005-4004 | Infinetsoftware | Cross-Site Scripting vulnerability in InfinetSoftware MyTemplateSite Search.ASP Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | 4.3 |
2005-12-05 | CVE-2005-4000 | Sitebeater | Cross-Site Scripting vulnerability in SiteBeater News Archive.ASP Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter. | 4.3 |
2005-12-05 | CVE-2005-3999 | Sitebeater | Cross-Site Scripting vulnerability in Sitebeater MP3 Catalog 2.0.3 Cross-site scripting (XSS) vulnerability in Search.asp in SiteBeater MP3 Catalog 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 4.3 |
2005-12-05 | CVE-2005-3998 | Solupress | Cross-Site Scripting vulnerability in Solupress News Search.ASP Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | 4.3 |
2005-12-07 | CVE-2005-4046 | SUN | Man In The Middle vulnerability in SUN products Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers to conduct man-in-the-middle (MITM) attacks and "compromise data privacy." | 4.0 |
2005-12-07 | CVE-2005-2923 | Ipswitch | Improper Input Validation vulnerability in Ipswitch Imail Server and Ipswitch Collaboration Suite The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory. | 4.0 |
2005-12-05 | CVE-2005-4002 | ESI Products | Remote Security vulnerability in WebEOC WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation. | 4.0 |
5 Low Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2005-12-05 | CVE-2005-3997 | ZEN Cart | Information Disclosure vulnerability in Zen Cart Zen Cart 1.2.6d and earlier, under certain PHP configurations, allows remote attackers to obtain sensitive information via direct requests to files in the admin/includes directory, including (1) graphs/banner_daily.php, (2) graphs/banner_infobox.php, (3) graphs/banner_yearly.php, (4) graphs/banner_monthly.php, (5) application_bottom.php, (6) attributes_preview.php, (7) modules/category_product_listing.php, (8) modules/copy_to_confirm.php, (9) modules/delete_product_confirm.php, and (10) modules/move_product_confirm.php, which leaks the web server path in the resulting error message. | 2.6 |
2005-12-11 | CVE-2005-4176 | Award | AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory. | 2.1 |
2005-12-11 | CVE-2005-4175 | Insyde | Unspecified vulnerability in Insyde Bios V190 Insyde BIOS V190 does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory. | 2.1 |
2005-12-10 | CVE-2005-4151 | PGP | Unspecified vulnerability in PGP Desktop 8.0/9.0 The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk. | 2.1 |
2005-12-09 | CVE-2005-4133 | SUN | Unspecified vulnerability in SUN Solaris 10.0 Sun Update Connection in Sun Solaris 10, when configured to use a web proxy, allows local users to obtain the proxy authentication password via (1) an unspecified vector and (2) proxy log files. | 2.1 |