CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24958  CVE-2007-1601  Candidate  ** DISPUTED ** Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files.  Assigned (20070322)  None (candidate not yet proposed)    View
27537  CVE-2007-4180  Candidate  ** DISPUTED ** Directory traversal vulnerability in data/inc/theme.php in Pluck 4.3, when register_globals is enabled, allows remote attackers to read arbitrary local files via a .. (dot dot) in the file parameter. NOTE: CVE and a reliable third party dispute this vulnerability because the code uses a a fixed argument when invoking fputs, which cannot be used to read files.  Assigned (20070807)  None (candidate not yet proposed)    View
24834  CVE-2007-1477  Candidate  ** DISPUTED ** Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation.  Assigned (20070316)  None (candidate not yet proposed)    View
27299  CVE-2007-3942  Candidate  ** DISPUTED ** Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray are defined before use.  Assigned (20070720)  None (candidate not yet proposed)    View
25769  CVE-2007-2412  Candidate  ** DISPUTED ** Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive information via a .. (dot dot) in the a[filepath] parameter. NOTE: a third party has disputed this issue because the a array is populated by a database query before use.  Assigned (20070430)  None (candidate not yet proposed)    View

Page 15 of 20943, showing 5 records out of 104715 total, starting on record 71, ending on 75

Actions