CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13903  CVE-2005-2697  Candidate  SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282.  Assigned (20050825)  None (candidate not yet proposed)    View
13904  CVE-2005-2698  Candidate  Cross-site scripting (XSS) vulnerability in browse.php in Nephp Publisher Enterprise 3.04 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded keywords parameter.  Assigned (20050825)  None (candidate not yet proposed)    View
13905  CVE-2005-2699  Candidate  Unrestricted file upload vulnerability in admin/admin.php in PHPKit 1.6.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a .php file to the content/images/ directory using images.php. NOTE: if a PHPKit administrator must already have access to the end system to install or modify configuration of the product, then this issue might not cross privilege boundaries, and should not be included in CVE.  Assigned (20050825)  None (candidate not yet proposed)    View
13891  CVE-2005-2685  Candidate  SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via a direct request to admin/PhpMyExplorer/editerfichier.php, then editing the desired file to contain the PHP code, as demonstrated using header.php in the fichier parameter. NOTE: it is possible that this vulnerability stems from PhpMyExplorer, which is a separate package.  Assigned (20050824)  None (candidate not yet proposed)    View
13892  CVE-2005-2686  Candidate  Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php.  Assigned (20050824)  None (candidate not yet proposed)    View

Page 18950 of 20943, showing 5 records out of 104715 total, starting on record 94746, ending on 94750

Actions