CVE-2005-1097
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges. Date published : 2005-04-13 http://securitytracker.com/id?1013673
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges. Date published : 2005-04-13 http://securitytracker.com/id?1013673
SQL injection vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to execute arbitrary SQL commands via the UserID parameter. Date published : 2005-04-13 http://www.securityfocus.com/bid/13049 http://www.hackerscenter.com/archive/view.asp?id=1865
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter. Date published : 2005-04-13 http://www.securityfocus.com/bid/13046 http://www.hackerscenter.com/archive/view.asp?id=1865
FTP Now 2.6.14 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges. Date published : 2005-04-13 http://www.osvdb.org/15296 http://securitytracker.com/id?1013657
Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code. Date published : 2005-04-13 http://www.securityfocus.com/bid/13048 http://forums.miranda-im.org/showthread.php?p=9624
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges. Date published : 2005-04-13 http://www.securityfocus.com/bid/13105 http://lostmon.blogspot.com/2005/04/deluxeftp-plain-text-passwords.html
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page. Date published : 2005-04-13 http://www.securityfocus.com/bid/13073...
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files. Date published : 2005-04-13 http://www.securityfocus.com/bid/13074 http://www.raffon.net/advisories/maxthon/multvulns.html
Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files. Date published : 2005-04-13 http://dcplusplus.sourceforge.net/index.php?t=8&s=1 http://www.osvdb.org/15433
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights. Date published : 2005-04-13 http://www.securityfocus.com/bid/13023 http://www.dameware.com/support/security/bulletin.asp?ID=SB5
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF...
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header. Date published : 2005-04-13 http://www.securityfocus.com/bid/13066 http://www.security.org.sg/vuln/anhttpd142n.html
Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files...
GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user’s contact list to execute arbitrary code via a GIF image with an improper height and width. Date published : 2005-04-13...