CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9855 | CVE-2004-1427 | Candidate | PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9854 | CVE-2004-1426 | Candidate | Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9853 | CVE-2004-1425 | Candidate | Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9852 | CVE-2004-1424 | Candidate | Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9851 | CVE-2004-1423 | Candidate | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php. | Assigned (20050212) | None (candidate not yet proposed) | View |
Page 18973 of 20943, showing 5 records out of 104715 total, starting on record 94861, ending on 94865