CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9847  CVE-2004-1419  Candidate  PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.  Assigned (20050212)  None (candidate not yet proposed)    View
9848  CVE-2004-1420  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter.  Assigned (20050212)  None (candidate not yet proposed)    View
9849  CVE-2004-1421  Candidate  Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.  Assigned (20050212)  None (candidate not yet proposed)    View
9850  CVE-2004-1422  Candidate  WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings.  Assigned (20050212)  None (candidate not yet proposed)    View
9851  CVE-2004-1423  Candidate  Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php.  Assigned (20050212)  None (candidate not yet proposed)    View

Page 19805 of 20943, showing 5 records out of 104715 total, starting on record 99021, ending on 99025

Actions