CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8230  CVE-2003-1406  Candidate  PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.  Assigned (20071019)  None (candidate not yet proposed)    View
8229  CVE-2003-1405  Candidate  DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3.  Assigned (20071019)  None (candidate not yet proposed)    View
8228  CVE-2003-1404  Candidate  DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.  Assigned (20071019)  None (candidate not yet proposed)    View
8227  CVE-2003-1403  Candidate  foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.  Assigned (20071019)  None (candidate not yet proposed)    View
8226  CVE-2003-1402  Candidate  PHP remote file inclusion vulnerability in hit.php for Kietu 2.0 and 2.3 allows remote attackers to execute arbitrary PHP code via the url_hit parameter, a different vulnerability than CVE-2006-5015.  Assigned (20071019)  None (candidate not yet proposed)    View

Page 19298 of 20943, showing 5 records out of 104715 total, starting on record 96486, ending on 96490

Actions