CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11581  CVE-2005-0375  Candidate  imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.  Assigned (20050213)  None (candidate not yet proposed)    View
11582  CVE-2005-0376  Candidate  PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.  Assigned (20050213)  None (candidate not yet proposed)    View
11583  CVE-2005-0377  Candidate  SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.  Assigned (20050213)  None (candidate not yet proposed)    View
11584  CVE-2005-0378  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Horde 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to prefs.php or (2) url parameter to index.php.  Assigned (20050213)  None (candidate not yet proposed)    View
11585  CVE-2005-0379  Candidate  Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php.  Assigned (20050213)  None (candidate not yet proposed)    View

Page 19787 of 20943, showing 5 records out of 104715 total, starting on record 98931, ending on 98935

Actions