CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13086  CVE-2005-1880  Candidate  everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.  Assigned (20050608)  None (candidate not yet proposed)    View
13087  CVE-2005-1881  Candidate  upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.  Assigned (20050608)  None (candidate not yet proposed)    View
13088  CVE-2005-1882  Candidate  PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.  Assigned (20050608)  None (candidate not yet proposed)    View
13089  CVE-2005-1883  Candidate  global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.  Assigned (20050608)  None (candidate not yet proposed)    View
13090  CVE-2005-1884  Candidate  Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.  Assigned (20050608)  None (candidate not yet proposed)    View

Page 19292 of 20943, showing 5 records out of 104715 total, starting on record 96456, ending on 96460

Actions