CVE-2004-2244
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to...
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to...
Phorum allows remote attackers to hijack sessions of other users by stealing and replaying the session hash in the phorum_uriauth parameter, as demonstrated using profile.php. NOTE: the affected version was reported to be 4.3.7,...
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attackers to inject arbitrary HTML or web script via the subject parameter. Date published : 2005-07-17 http://www.securityfocus.com/bid/10822 http://phorum.org/cvs-changelog-5.txt
Cross-site scripting (XSS) vulnerability in Phorum 5.0.11 and earlier allows remote attackers to inject arbitrary HTML or web script via search.php. NOTE: some sources have reported that the affected file is read.php, but this...
Multiple SQL injection vulnerabilities in Phorum 5.0.11 and earlier allow remote attackers to modify SQL statements via (1) the query string in read.php or (2) unknown vectors in file.php. Date published : 2005-07-17 http://www.securityfocus.com/bid/11538...
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code. Date published : 2005-07-17 http://www.securityfocus.com/bid/10962 http://archives.neohapsis.com/archives/bugtraq/2004-08/0226.html
** DISPUTED ** Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors. NOTE: in a followup post, it was observed that the source code used constants that,...
Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts." Date published : 2005-07-17 http://moodle.org/doc/?file=releaseold.html http://www.osvdb.org/8522
Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting. Date published : 2005-07-17 http://moodle.org/doc/?file=releaseold.html http://www.osvdb.org/8090
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text. Date published : 2005-07-17 http://moodle.org/doc/?file=releaseold.html http://www.osvdb.org/7711
Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators. Date published : 2005-07-17 http://moodle.org/doc/?file=releaseold.html http://www.osvdb.org/7711
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors. Date published : 2005-07-17 http://www.securityfocus.com/bid/10697 http://moodle.org/doc/?file=releaseold.html
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements. Date published : 2005-07-17 http://www.securityfocus.com/bid/11608 http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/mod/glossary/sql.php?r1=1.15.2.2&r2=1.15.2.3
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files. Date published : 2005-07-17 http://www.securityfocus.com/bid/10808 http://www.idefense.com/application/poi/display?id=82&type=vulnerabilities