CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9855  CVE-2004-1427  Candidate  PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng parameter to cause main.inc to be loaded.  Assigned (20050212)  None (candidate not yet proposed)    View
9854  CVE-2004-1426  Candidate  Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9853  CVE-2004-1425  Candidate  Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9852  CVE-2004-1424  Candidate  Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9851  CVE-2004-1423  Candidate  Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.  Assigned (20050212)  None (candidate not yet proposed)    View

Page 18973 of 20943, showing 5 records out of 104715 total, starting on record 94861, ending on 94865

Actions