CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25099  CVE-2007-1742  Candidate  suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html_backup" and "htmleditor" under an "html" directory. NOTE: the researcher, who is reliable, claims that the vendor disputes the issue because "the attacks described rely on an insecure server configuration" in which the user "has write access to the document root."  Assigned (20070328)  None (candidate not yet proposed)    View
90635  CVE-2016-3816  Candidate  The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28402240.  Assigned (20160330)  None (candidate not yet proposed)    View
25355  CVE-2007-1998  Candidate  Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php.  Assigned (20070412)  None (candidate not yet proposed)    View
90891  CVE-2016-4072  Candidate  The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of characters by the phar_analyze_path function in ext/phar/phar.c.  Assigned (20160423)  None (candidate not yet proposed)    View
25611  CVE-2007-2254  Candidate  PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 1526 of 20943, showing 5 records out of 104715 total, starting on record 7626, ending on 7630

Actions