CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
14251 | CVE-2005-3045 | Candidate | SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field. | Assigned (20050923) | None (candidate not yet proposed) | View | |
14252 | CVE-2005-3046 | Candidate | SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field. | Assigned (20050923) | None (candidate not yet proposed) | View | |
14253 | CVE-2005-3047 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php. | Assigned (20050923) | None (candidate not yet proposed) | View | |
14254 | CVE-2005-3048 | Candidate | Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file. | Assigned (20050923) | None (candidate not yet proposed) | View | |
14255 | CVE-2005-3049 | Candidate | PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file. | Assigned (20050923) | None (candidate not yet proposed) | View |
Page 18878 of 20943, showing 5 records out of 104715 total, starting on record 94386, ending on 94390