CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8005  CVE-2003-1181  Candidate  Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invokes the phpinfo() function.  Assigned (20050504)  None (candidate not yet proposed)    View
8004  CVE-2003-1180  Candidate  Directory traversal vulnerability in Advanced Poll 2.0.2 allows remote attackers to read arbitrary files or inject arbitrary local PHP files via .. sequences in the base_path or pollvars[lang] parameters to the admin files (1) index.php, (2) admin_tpl_new.php, (3) admin_tpl_misc_new.php, (4) admin_templates_misc.php, (5) admin_templates.php, (6) admin_stats.php, (7) admin_settings.php, (8) admin_preview.php, (9) admin_password.php, (10) admin_logout.php, (11) admin_license.php, (12) admin_help.php, (13) admin_embed.php, (14) admin_edit.php, or (15) admin_comment.php.  Assigned (20050504)  None (candidate not yet proposed)    View
8003  CVE-2003-1179  Candidate  Multiple PHP remote file inclusion vulnerabilities in Advanced Poll 2.0.2 allow remote attackers to execute arbitrary PHP code via the include_path parameter in (1) booth.php, (2) png.php, (3) poll_ssi.php, or (4) popup.php, the (5) base_path parameter to common.inc.php.  Assigned (20050504)  None (candidate not yet proposed)    View
8002  CVE-2003-1178  Candidate  Eval injection vulnerability in comments.php in Advanced Poll 2.0.2 allows remote attackers to execute arbitrary PHP code via the (1) id, (2) template_set, or (3) action parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
8001  CVE-2003-1177  Candidate  Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 19343 of 20943, showing 5 records out of 104715 total, starting on record 96711, ending on 96715

Actions