CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9850 | CVE-2004-1422 | Candidate | WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9849 | CVE-2004-1421 | Candidate | Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9848 | CVE-2004-1420 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9847 | CVE-2004-1419 | Candidate | PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9846 | CVE-2004-1418 | Candidate | Cross-site scripting (XSS) vulnerability in WPKontakt 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail address, which is not quoted when a parsing error is generated. | Assigned (20050212) | None (candidate not yet proposed) | View |
Page 18974 of 20943, showing 5 records out of 104715 total, starting on record 94866, ending on 94870