CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8230 | CVE-2003-1406 | Candidate | PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8229 | CVE-2003-1405 | Candidate | DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8228 | CVE-2003-1404 | Candidate | DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8227 | CVE-2003-1403 | Candidate | foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | Assigned (20071019) | None (candidate not yet proposed) | View | |
8226 | CVE-2003-1402 | Candidate | PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015. | Assigned (20071019) | None (candidate not yet proposed) | View |
Page 19298 of 20943, showing 5 records out of 104715 total, starting on record 96486, ending on 96490