CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9847 | CVE-2004-1419 | Candidate | PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9848 | CVE-2004-1420 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in header.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) site_title or (2) http_images parameter. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9849 | CVE-2004-1421 | Candidate | Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9850 | CVE-2004-1422 | Candidate | WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php settings. | Assigned (20050212) | None (candidate not yet proposed) | View | |
9851 | CVE-2004-1423 | Candidate | Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law Office (VLO) and other products, allow remote attackers to execute arbitrary PHP code via a URL in the phpc_root_path parameter to (1) includes/calendar.php or (2) includes/setup.php. | Assigned (20050212) | None (candidate not yet proposed) | View |
Page 19805 of 20943, showing 5 records out of 104715 total, starting on record 99021, ending on 99025