CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11926  CVE-2005-0720  Candidate  PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.  Assigned (20050312)  None (candidate not yet proposed)    View
11927  CVE-2005-0721  Candidate  PHP remote file inclusion vulnerability in modules.php in eXPerience2 allows remote attackers to execute arbitrary PHP code by modifying the file parameter to reference a URL on a remote web server that contains the code.  Assigned (20050312)  None (candidate not yet proposed)    View
11928  CVE-2005-0722  Candidate  eXPerience2 allows remote attackers to obtain the full path for the web root via a direct request to modules.php without any parameters, which leaks the path in a PHP error message.  Assigned (20050312)  None (candidate not yet proposed)    View
11929  CVE-2005-0723  Candidate  Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php.  Assigned (20050312)  None (candidate not yet proposed)    View
11930  CVE-2005-0724  Candidate  paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or (12) admin.php, which reveals the path in a PHP error message.  Assigned (20050312)  None (candidate not yet proposed)    View

Page 19651 of 20943, showing 5 records out of 104715 total, starting on record 98251, ending on 98255

Actions