CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13587 | CVE-2005-2381 | Candidate | PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message. | Assigned (20050726) | None (candidate not yet proposed) | View | |
79123 | CVE-2015-1846 | Candidate | unzoo allows remote attackers to cause a denial of service (infinite loop and resource consumption) via unspecified vectors to the (1) ExtrArch or (2) ListArch function, related to pointer handling. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13843 | CVE-2005-2637 | Candidate | Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php. | Assigned (20050820) | None (candidate not yet proposed) | View | |
79379 | CVE-2015-2102 | Candidate | SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter. | Assigned (20150227) | None (candidate not yet proposed) | View | |
14099 | CVE-2005-2893 | Candidate | Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login. | Assigned (20050914) | None (candidate not yet proposed) | View |
Page 1923 of 20943, showing 5 records out of 104715 total, starting on record 9611, ending on 9615