CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11996  CVE-2005-0790  Candidate  phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7) remotehtmlview.php, (8) click.php, (9) adcontent.php, which reveal the path in a PHP error message.  Assigned (20050320)  None (candidate not yet proposed)    View
11997  CVE-2005-0791  Candidate  Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.  Assigned (20050320)  None (candidate not yet proposed)    View
11998  CVE-2005-0792  Candidate  SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to index.php or (2) page parameter to zpanel.php.  Assigned (20050320)  None (candidate not yet proposed)    View
11999  CVE-2005-0793  Candidate  PHP remote file inclusion vulnerability in zpanel.php in ZPanel allows remote attackers to (1) execute arbitrary PHP code in ZPanel 2.0 or (2) include local files in ZPanel 2.5 beta 10 and earlier by modifying the page parameter.  Assigned (20050320)  None (candidate not yet proposed)    View
12000  CVE-2005-0794  Candidate  ZPanel 2.0 and 2.5 beta 10 does not remove or protect installation scripts after they have been used, which allows remote attackers to reinstall the software and possibly cause a denial of service via a direct request to install.php.  Assigned (20050320)  None (candidate not yet proposed)    View

Page 19633 of 20943, showing 5 records out of 104715 total, starting on record 98161, ending on 98165

Actions