CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12903  CVE-2005-1697  Candidate  The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.  Assigned (20050524)  None (candidate not yet proposed)    View
12904  CVE-2005-1698  Candidate  PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, or (9) button.php in the pnblocks directory in the Blocks module, (10) config.php in the NS-Multisites (aka Multisites) module, or (11) xmlrpc.php, which reveals the path in an error message.  Assigned (20050524)  None (candidate not yet proposed)    View
12905  CVE-2005-1699  Candidate  Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.  Assigned (20050524)  None (candidate not yet proposed)    View
12906  CVE-2005-1700  Candidate  SQL injection vulnerability in pnadmin.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to execute arbitrary SQL commands via the riga[0] parameter.  Assigned (20050524)  None (candidate not yet proposed)    View
12907  CVE-2005-1701  Candidate  SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.  Assigned (20050524)  None (candidate not yet proposed)    View

Page 19338 of 20943, showing 5 records out of 104715 total, starting on record 96686, ending on 96690

Actions