CVE-2005-2527
published 2005-12-31CVE-2005-2527: Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack…
PriorityP410low1.2CVSS 2.0
AVLACHAuNCNIPAN
EPSS
0.32%
24.3th percentile
Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | java | <= 1.4.2_release1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
PHPPost 1.0 - 'mail.php?user' Cross-Site Scripting
exploitdb·2005-11-21
CVE-2005-3770 PHPPost 1.0 - 'mail.php?user' Cross-Site Scripting
PHPPost 1.0 - 'mail.php?user' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15524/info
PHP-Post is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. The attacker may also be able to steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/phpp/mail.php?user='%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E
Exploit-DB
PHPPost 1.0 - 'profile.php?user' Cross-Site Scripting
exploitdb·2005-11-21
CVE-2005-3770 PHPPost 1.0 - 'profile.php?user' Cross-Site Scripting
PHPPost 1.0 - 'profile.php?user' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15524/info
PHP-Post is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. The attacker may also be able to steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/phpp/profile.php?user='%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E
Exploit-DB
Ekinboard 1.0.3 - 'profile.php' Cross-Site Scripting
exploitdb·2005-11-15
CVE-2005-3638 Ekinboard 1.0.3 - 'profile.php' Cross-Site Scripting
Ekinboard 1.0.3 - 'profile.php' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15447/info
Ekinboard is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
http://www.example.com/ekinboard/profile.php?id=2'%3E%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
Exploit-DB
VUBB - 'index.php' Cross-Site Scripting
exploitdb·2005-11-01
CVE-2005-3512 VUBB - 'index.php' Cross-Site Scripting
VUBB - 'index.php' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15260/info
VUBB is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
http://www.example.com/forum/index.php?act=newreply&t='>%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&f=6
Exploit-DB
GCards 1.43 - 'news.php' SQL Injection
exploitdb·2005-10-26
CVE-2005-3408 GCards 1.43 - 'news.php' SQL Injection
GCards 1.43 - 'news.php' SQL Injection
---
source: https://www.securityfocus.com/bid/15216/info
gCards is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
http://www.example.com/ecards1/news.php?limit=%2527
Exploit-DB
Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
exploitdb·2005-10-20
CVE-2005-3514 Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15149/info
Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/board/newtopic.php?forumID='%3C/a>%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
Exploit-DB
Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
exploitdb·2005-10-20
CVE-2005-3514 Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15149/info
Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/board/quote.php?forumID='%3C/a>%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
Exploit-DB
Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
exploitdb·2005-10-20
CVE-2005-3515 Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15149/info
Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/topsites/recommend.php?ID='%3C/a>%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
Exploit-DB
Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
exploitdb·2005-10-20
CVE-2005-3516 Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/15149/info
Chipmunk products are prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the applications to properly sanitize user-supplied input.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
http://www.example.com/directory/recommend.php?entryID='%3C/a>%3CIFRAME%20SRC=javascript:alert(%2527xss%2527)%3E%3C/IFRAME%3E
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=302266http://lists.apple.com/archives/security-announce/2005/Sep/msg00001.htmlhttp://secunia.com/advisories/16808http://www.ciac.org/ciac/bulletins/p-306.shtmlhttp://www.securityfocus.com/bid/14825http://www.vupen.com/english/advisories/2005/1734https://exchange.xforce.ibmcloud.com/vulnerabilities/22262http://docs.info.apple.com/article.html?artnum=302266http://lists.apple.com/archives/security-announce/2005/Sep/msg00001.htmlhttp://secunia.com/advisories/16808http://www.ciac.org/ciac/bulletins/p-306.shtmlhttp://www.securityfocus.com/bid/14825http://www.vupen.com/english/advisories/2005/1734https://exchange.xforce.ibmcloud.com/vulnerabilities/22262
2005-12-31
Published