CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13086 | CVE-2005-1880 | Candidate | everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget. | Assigned (20050608) | None (candidate not yet proposed) | View | |
13087 | CVE-2005-1881 | Candidate | upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code. | Assigned (20050608) | None (candidate not yet proposed) | View | |
13088 | CVE-2005-1882 | Candidate | PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter. | Assigned (20050608) | None (candidate not yet proposed) | View | |
13089 | CVE-2005-1883 | Candidate | global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter. | Assigned (20050608) | None (candidate not yet proposed) | View | |
13090 | CVE-2005-1884 | Candidate | Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter. | Assigned (20050608) | None (candidate not yet proposed) | View |
Page 19292 of 20943, showing 5 records out of 104715 total, starting on record 96456, ending on 96460