| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-4281 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi. | |||
| CVE-2005-4282 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML, possibly via the root parameter to zaygo.cgi. | |||
| CVE-2005-4283 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cgi. | |||
| CVE-2005-4284 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the… | |||
| CVE-2005-4285 | 0.03 | — | 0.02 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters. | |||
| CVE-2005-4286 | 0.00 | — | 0.01 | Dec 16, 2005 | Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php. | |||
| CVE-2005-4287 | 0.03 | — | 0.05 | Dec 16, 2005 | PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php. | |||
| CVE-2005-4288 | 0.03 | — | 0.02 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287. | |||
| CVE-2005-4289 | 0.03 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter. | |||
| CVE-2005-4290 | 0.03 | — | 0.02 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters. | |||
| CVE-2005-4291 | 0.03 | — | 0.02 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters. | |||
| CVE-2005-4292 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords parameter in the Quick Find feature. | |||
| CVE-2005-4293 | 0.03 | — | 0.02 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter. | |||
| CVE-2005-4294 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the username in the login page. | |||
| CVE-2005-4295 | 0.00 | — | 0.01 | Dec 16, 2005 | Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||
| CVE-2005-4296 | 0.03 | — | 0.03 | Dec 16, 2005 | AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request. | |||
| CVE-2005-4271 | 0.00 | — | 0.00 | Dec 15, 2005 | Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code. | |||
| CVE-2005-4272 | 0.01 | — | 0.09 | Dec 15, 2005 | Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal. | |||
| CVE-2005-4273 | 0.00 | — | 0.00 | Dec 15, 2005 | Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files. | |||
| CVE-2005-4274 | 0.00 | — | 0.01 | Dec 15, 2005 | Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input." | |||
| CVE-2005-4269 | 0.00 | — | 0.05 | Dec 15, 2005 | mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office… | |||
| CVE-2005-4270 | 0.03 | — | 0.05 | Dec 15, 2005 | Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field. | |||
| CVE-2005-4268 | 0.00 | — | 0.01 | Dec 15, 2005 | Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits. | |||
| CVE-2005-4243 | 0.03 | — | 0.05 | Dec 15, 2005 | Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr parameters in customer.tickets.view.php; (5) subrackingid parameter in… | |||
| CVE-2005-4248 | 0.00 | — | 0.01 | Dec 15, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, and (3) mycompany/categories.php. | |||
| CVE-2005-4249 | 0.00 | — | 0.02 | Dec 15, 2005 | ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory. | |||
| CVE-2005-4253 | 0.00 | — | 0.01 | Dec 15, 2005 | Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160. | |||
| CVE-2005-4254 | 0.03 | — | 0.01 | Dec 15, 2005 | SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2005-4255 | 0.03 | — | 0.02 | Dec 15, 2005 | Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter. | |||
| CVE-2005-4256 | 0.03 | — | 0.02 | Dec 15, 2005 | Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition,… | |||
| CVE-2005-4257 | 0.00 | — | 0.01 | Dec 15, 2005 | Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the details are obtained… | |||
| CVE-2005-4258 | 0.00 | — | 0.02 | Dec 15, 2005 | Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are… | |||
| CVE-2005-4259 | 0.03 | — | 0.01 | Dec 15, 2005 | Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown;… | |||
| CVE-2005-4260 | 0.03 | — | 0.02 | Dec 15, 2005 | Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically… | |||
| CVE-2005-4261 | 0.00 | — | 0.02 | Dec 15, 2005 | Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this… | |||
| CVE-2005-4262 | 0.03 | — | 0.01 | Dec 15, 2005 | Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263). | |||
| CVE-2005-4263 | 0.03 | — | 0.01 | Dec 15, 2005 | SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter. | |||
| CVE-2005-4264 | 0.00 | — | 0.01 | Dec 15, 2005 | Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter. | |||
| CVE-2005-4266 | 0.00 | — | 0.01 | Dec 15, 2005 | WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value. | |||
| CVE-2005-1928 | 0.00 | — | 0.04 | Dec 14, 2005 | Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of… | |||
| CVE-2005-1929 | 0.00 | — | 0.05 | Dec 14, 2005 | Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped"… | |||
| CVE-2005-1930 | 0.00 | — | 0.02 | Dec 14, 2005 | Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary… | |||
| CVE-2005-3360 | 0.00 | — | 0.00 | Dec 14, 2005 | The installation of Trend Micro PC-Cillin Internet Security 2005 12.00 build 1244, and probably previous versions, uses insecure default ACLs, which allows local users to cause a denial of service (disabled service) and gain system privileges by modifying or moving critical… | |||
| CVE-2005-3358 | 0.00 | — | 0.01 | Dec 14, 2005 | Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs. | |||
| CVE-2005-4242 | 0.00 | — | 0.01 | Dec 14, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data. | |||
| CVE-2005-2829 | 0.01 | — | 0.19 | Dec 14, 2005 | Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box… | |||
| CVE-2005-2830 | 0.03 | — | 0.35 | Dec 14, 2005 | Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability." | |||
| CVE-2005-2831 | 0.02 | — | 0.30 | Dec 14, 2005 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet… | |||
| CVE-2005-3903 | 0.00 | — | 0.01 | Dec 14, 2005 | Buffer overflow in uidadmin in SCO Unixware 7.1.3 and 7.1.4 allows local users to execute arbitrary code via a -S (scheme) argument that specifies a large file, a different vulnerability than CVE-2001-1063. | |||
| CVE-2005-4211 | 0.04 | — | 0.09 | Dec 14, 2005 | PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable. |
- CVE-2005-4281Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi.
- CVE-2005-4282Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Zaygo DomainCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML, possibly via the root parameter to zaygo.cgi.
- CVE-2005-4283Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in The CITY Shop 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via parameters to the search module, possibly SKey to store.cgi.
- CVE-2005-4284Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the…
- CVE-2005-4285Dec 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters.
- CVE-2005-4286Dec 16, 2005risk 0.00cvss —epss 0.01
Unspecified vulnerability in PhpLogCon before 1.2.2 allows remote attackers to use arbitrary profiles via unknown vectors involving "'smart' values for userid and password," probably involving an SQL injection vulnerability in the (1) pass and (2) usr parameters in submit.php.
- CVE-2005-4287Dec 16, 2005risk 0.03cvss —epss 0.05
PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.
- CVE-2005-4288Dec 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.
- CVE-2005-4289Dec 16, 2005risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.
- CVE-2005-4290Dec 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in index.cgi in ECW-Cart 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) kword, (2) max, (3) min, (4) comp, and (5) f parameters.
- CVE-2005-4291Dec 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in cart.cgi in ECTOOLS Onlineshop 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) product, (2) category, and (3) uid parameters.
- CVE-2005-4292Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in CommerceSQL 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keywords parameter in the Quick Find feature.
- CVE-2005-4293Dec 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.
- CVE-2005-4294Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via the username in the login page.
- CVE-2005-4295Dec 16, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVE-2005-4296Dec 16, 2005risk 0.03cvss —epss 0.03
AppServ Open Project 2.5.3 allows remote attackers to cause a denial of service via a large HTTP request.
- CVE-2005-4271Dec 15, 2005risk 0.00cvss —epss 0.00
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.
- CVE-2005-4272Dec 15, 2005risk 0.01cvss —epss 0.09
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
- CVE-2005-4273Dec 15, 2005risk 0.00cvss —epss 0.00
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
- CVE-2005-4274Dec 15, 2005risk 0.00cvss —epss 0.01
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input."
- CVE-2005-4269Dec 15, 2005risk 0.00cvss —epss 0.05
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office…
- CVE-2005-4270Dec 15, 2005risk 0.03cvss —epss 0.05
Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.
- CVE-2005-4268Dec 15, 2005risk 0.00cvss —epss 0.01
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
- CVE-2005-4243Dec 15, 2005risk 0.03cvss —epss 0.05
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr parameters in customer.tickets.view.php; (5) subrackingid parameter in…
- CVE-2005-4248Dec 15, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, and (3) mycompany/categories.php.
- CVE-2005-4249Dec 15, 2005risk 0.00cvss —epss 0.02
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.
- CVE-2005-4253Dec 15, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160.
- CVE-2005-4254Dec 15, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2005-4255Dec 15, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.
- CVE-2005-4256Dec 15, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID. In addition,…
- CVE-2005-4257Dec 15, 2005risk 0.00cvss —epss 0.01
Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the details are obtained…
- CVE-2005-4258Dec 15, 2005risk 0.00cvss —epss 0.02
Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are…
- CVE-2005-4259Dec 15, 2005risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of this issue is unknown;…
- CVE-2005-4260Dec 15, 2005risk 0.03cvss —epss 0.02
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but is automatically…
- CVE-2005-4261Dec 15, 2005risk 0.00cvss —epss 0.02
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this…
- CVE-2005-4262Dec 15, 2005risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).
- CVE-2005-4263Dec 15, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.
- CVE-2005-4264Dec 15, 2005risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.
- CVE-2005-4266Dec 15, 2005risk 0.00cvss —epss 0.01
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
- CVE-2005-1928Dec 14, 2005risk 0.00cvss —epss 0.04
Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of…
- CVE-2005-1929Dec 14, 2005risk 0.00cvss —epss 0.05
Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped"…
- CVE-2005-1930Dec 14, 2005risk 0.00cvss —epss 0.02
Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote attackers to read arbitrary…
- CVE-2005-3360Dec 14, 2005risk 0.00cvss —epss 0.00
The installation of Trend Micro PC-Cillin Internet Security 2005 12.00 build 1244, and probably previous versions, uses insecure default ACLs, which allows local users to cause a denial of service (disabled service) and gain system privileges by modifying or moving critical…
- CVE-2005-3358Dec 14, 2005risk 0.00cvss —epss 0.01
Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.
- CVE-2005-4242Dec 14, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.
- CVE-2005-2829Dec 14, 2005risk 0.01cvss —epss 0.19
Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box…
- CVE-2005-2830Dec 14, 2005risk 0.03cvss —epss 0.35
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."
- CVE-2005-2831Dec 14, 2005risk 0.02cvss —epss 0.30
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet…
- CVE-2005-3903Dec 14, 2005risk 0.00cvss —epss 0.01
Buffer overflow in uidadmin in SCO Unixware 7.1.3 and 7.1.4 allows local users to execute arbitrary code via a -S (scheme) argument that specifies a large file, a different vulnerability than CVE-2001-1063.
- CVE-2005-4211Dec 14, 2005risk 0.04cvss —epss 0.09
PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.