CVE List

Id CVE No. Status Description Phase Votes Comments Actions
14251  CVE-2005-3045  Candidate  SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.  Assigned (20050923)  None (candidate not yet proposed)    View
14252  CVE-2005-3046  Candidate  SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.  Assigned (20050923)  None (candidate not yet proposed)    View
14253  CVE-2005-3047  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.  Assigned (20050923)  None (candidate not yet proposed)    View
14254  CVE-2005-3048  Candidate  Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file.  Assigned (20050923)  None (candidate not yet proposed)    View
14255  CVE-2005-3049  Candidate  PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.  Assigned (20050923)  None (candidate not yet proposed)    View

Page 18878 of 20943, showing 5 records out of 104715 total, starting on record 94386, ending on 94390

Actions