CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13458  CVE-2005-2252  Candidate  PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.  Assigned (20050713)  None (candidate not yet proposed)    View
13459  CVE-2005-2253  Candidate  SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.  Assigned (20050713)  None (candidate not yet proposed)    View
13460  CVE-2005-2254  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there is evidence that viewnews.php and login.php may not be part of the PhpAuction product, so they are not included in this description.  Assigned (20050713)  None (candidate not yet proposed)    View
13461  CVE-2005-2255  Candidate  Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.  Assigned (20050713)  None (candidate not yet proposed)    View
13462  CVE-2005-2256  Candidate  Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.  Assigned (20050713)  None (candidate not yet proposed)    View

Page 19136 of 20943, showing 5 records out of 104715 total, starting on record 95676, ending on 95680

Actions