| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-2192 | 0.03 | — | 0.04 | Jul 11, 2005 | SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack. | |||
| CVE-2005-2193 | 0.00 | — | 0.01 | Jul 11, 2005 | SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the… | |||
| CVE-2005-2197 | 0.00 | — | 0.01 | Jul 11, 2005 | SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php. | |||
| CVE-2005-2198 | 0.00 | — | 0.03 | Jul 11, 2005 | PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter. | |||
| CVE-2005-2199 | 0.04 | — | 0.10 | Jul 11, 2005 | PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable. | |||
| CVE-2005-2200 | 0.00 | — | 0.02 | Jul 11, 2005 | Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication. | |||
| CVE-2005-2201 | 0.00 | — | 0.02 | Jul 11, 2005 | Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests. | |||
| CVE-2005-2202 | 0.00 | — | 0.02 | Jul 11, 2005 | Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||
| CVE-2005-2203 | 0.00 | — | 0.01 | Jul 11, 2005 | login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php. | |||
| CVE-2005-2204 | 0.00 | — | 0.02 | Jul 11, 2005 | Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3)… | |||
| CVE-2005-2205 | 0.00 | — | 0.02 | Jul 11, 2005 | The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. | |||
| CVE-2005-2206 | 0.00 | — | 0.01 | Jul 11, 2005 | Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp. | |||
| CVE-2005-2207 | 0.00 | — | 0.01 | Jul 11, 2005 | Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |||
| CVE-2005-2208 | 0.03 | — | 0.03 | Jul 11, 2005 | PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message. | |||
| CVE-2005-2209 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2005 | Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users. | ||
| CVE-2005-2210 | 0.03 | — | 0.04 | Jul 11, 2005 | Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL. | |||
| CVE-2005-2211 | 0.00 | — | 0.00 | Jul 11, 2005 | Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR. | |||
| CVE-2005-2212 | 0.00 | — | 0.01 | Jul 11, 2005 | Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository. | |||
| CVE-2005-2213 | 0.00 | — | 0.03 | Jul 11, 2005 | Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams. | |||
| CVE-2005-2214 | 0.00 | — | 0.00 | Jul 11, 2005 | apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords. | |||
| CVE-2005-2175 | 0.03 | — | 0.05 | Jul 9, 2005 | The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies. | |||
| CVE-2005-2176 | 0.03 | — | 0.04 | Jul 9, 2005 | Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies. | |||
| CVE-2005-2173 | 0.00 | — | 0.01 | Jul 8, 2005 | The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi. | |||
| CVE-2005-2174 | 0.00 | — | 0.01 | Jul 8, 2005 | Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete. | |||
| CVE-2005-1841 | 0.00 | — | 0.01 | Jul 7, 2005 | The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it. | |||
| CVE-2005-1916 | Med | 0.36 | 5.5 | 0.00 | Jul 6, 2005 | linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files. | ||
| CVE-2005-2096 | 0.00 | — | 0.06 | Jul 6, 2005 | zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file. | |||
| CVE-2005-2147 | 0.00 | — | 0.01 | Jul 6, 2005 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts. | |||
| CVE-2005-2148 | 0.00 | — | 0.03 | Jul 6, 2005 | Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which… | |||
| CVE-2005-2149 | 0.00 | — | 0.02 | Jul 6, 2005 | config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks. | |||
| CVE-2005-2151 | 0.00 | — | 0.01 | Jul 6, 2005 | spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption. | |||
| CVE-2005-2152 | 0.00 | — | 0.01 | Jul 6, 2005 | SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article. | |||
| CVE-2005-2153 | 0.00 | — | 0.01 | Jul 6, 2005 | SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable. | |||
| CVE-2005-2154 | 0.03 | — | 0.02 | Jul 6, 2005 | PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter. | |||
| CVE-2005-2155 | 0.03 | — | 0.03 | Jul 6, 2005 | PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter. | |||
| CVE-2005-2156 | 0.00 | — | 0.01 | Jul 6, 2005 | SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter. | |||
| CVE-2005-2157 | 0.03 | — | 0.02 | Jul 6, 2005 | PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter. | |||
| CVE-2005-2158 | 0.00 | — | 0.01 | Jul 6, 2005 | A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845. | |||
| CVE-2005-2159 | 0.00 | — | 0.01 | Jul 6, 2005 | mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request. | |||
| CVE-2005-2160 | Hig | 0.49 | 7.5 | 0.02 | Jul 6, 2005 | IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information. | ||
| CVE-2005-2161 | 0.00 | — | 0.01 | Jul 6, 2005 | Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags. | |||
| CVE-2005-2162 | 0.03 | — | 0.02 | Jul 6, 2005 | PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter. | |||
| CVE-2005-2163 | 0.03 | — | 0.02 | Jul 6, 2005 | Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |||
| CVE-2005-2164 | 0.00 | — | 0.01 | Jul 6, 2005 | SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |||
| CVE-2005-2165 | 0.00 | — | 0.02 | Jul 6, 2005 | read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters. | |||
| CVE-2005-2166 | 0.00 | — | 0.01 | Jul 6, 2005 | SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |||
| CVE-2005-2167 | 0.00 | — | 0.01 | Jul 6, 2005 | Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter. | |||
| CVE-2005-2168 | 0.00 | — | 0.01 | Jul 6, 2005 | delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter. | |||
| CVE-2005-2169 | 0.00 | — | 0.02 | Jul 6, 2005 | Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to… | |||
| CVE-2005-0360 | 0.01 | — | 0.12 | Jul 5, 2005 | The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files. |
- CVE-2005-2192Jul 11, 2005risk 0.03cvss —epss 0.04
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
- CVE-2005-2193Jul 11, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the…
- CVE-2005-2197Jul 11, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.
- CVE-2005-2198Jul 11, 2005risk 0.00cvss —epss 0.03
PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.
- CVE-2005-2199Jul 11, 2005risk 0.04cvss —epss 0.10
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.
- CVE-2005-2200Jul 11, 2005risk 0.00cvss —epss 0.02
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.
- CVE-2005-2201Jul 11, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.
- CVE-2005-2202Jul 11, 2005risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- CVE-2005-2203Jul 11, 2005risk 0.00cvss —epss 0.01
login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.
- CVE-2005-2204Jul 11, 2005risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3)…
- CVE-2005-2205Jul 11, 2005risk 0.00cvss —epss 0.02
The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
- CVE-2005-2206Jul 11, 2005risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.
- CVE-2005-2207Jul 11, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.
- CVE-2005-2208Jul 11, 2005risk 0.03cvss —epss 0.03
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
- risk 0.36cvss 5.5epss 0.00
Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.
- CVE-2005-2210Jul 11, 2005risk 0.03cvss —epss 0.04
Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.
- CVE-2005-2211Jul 11, 2005risk 0.00cvss —epss 0.00
Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.
- CVE-2005-2212Jul 11, 2005risk 0.00cvss —epss 0.01
Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.
- CVE-2005-2213Jul 11, 2005risk 0.00cvss —epss 0.03
Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.
- CVE-2005-2214Jul 11, 2005risk 0.00cvss —epss 0.00
apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.
- CVE-2005-2175Jul 9, 2005risk 0.03cvss —epss 0.05
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
- CVE-2005-2176Jul 9, 2005risk 0.03cvss —epss 0.04
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
- CVE-2005-2173Jul 8, 2005risk 0.00cvss —epss 0.01
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
- CVE-2005-2174Jul 8, 2005risk 0.00cvss —epss 0.01
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
- CVE-2005-1841Jul 7, 2005risk 0.00cvss —epss 0.01
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
- risk 0.36cvss 5.5epss 0.00
linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
- CVE-2005-2096Jul 6, 2005risk 0.00cvss —epss 0.06
zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
- CVE-2005-2147Jul 6, 2005risk 0.00cvss —epss 0.01
Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.
- CVE-2005-2148Jul 6, 2005risk 0.00cvss —epss 0.03
Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which…
- CVE-2005-2149Jul 6, 2005risk 0.00cvss —epss 0.02
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
- CVE-2005-2151Jul 6, 2005risk 0.00cvss —epss 0.01
spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.
- CVE-2005-2152Jul 6, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.
- CVE-2005-2153Jul 6, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.
- CVE-2005-2154Jul 6, 2005risk 0.03cvss —epss 0.02
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.
- CVE-2005-2155Jul 6, 2005risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
- CVE-2005-2156Jul 6, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
- CVE-2005-2157Jul 6, 2005risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.
- CVE-2005-2158Jul 6, 2005risk 0.00cvss —epss 0.01
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.
- CVE-2005-2159Jul 6, 2005risk 0.00cvss —epss 0.01
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
- risk 0.49cvss 7.5epss 0.02
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
- CVE-2005-2161Jul 6, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
- CVE-2005-2162Jul 6, 2005risk 0.03cvss —epss 0.02
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
- CVE-2005-2163Jul 6, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
- CVE-2005-2164Jul 6, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
- CVE-2005-2165Jul 6, 2005risk 0.00cvss —epss 0.02
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
- CVE-2005-2166Jul 6, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
- CVE-2005-2167Jul 6, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
- CVE-2005-2168Jul 6, 2005risk 0.00cvss —epss 0.01
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
- CVE-2005-2169Jul 6, 2005risk 0.00cvss —epss 0.02
Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to…
- CVE-2005-0360Jul 5, 2005risk 0.01cvss —epss 0.12
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.