CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25077  CVE-2007-1720  Candidate  Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file.  Assigned (20070327)  None (candidate not yet proposed)    View
90613  CVE-2016-3794  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3814. Reason: This candidate is a reservation duplicate of CVE-2016-3814. Notes: All CVE users should reference CVE-2016-3814 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20160330)  None (candidate not yet proposed)    View
25333  CVE-2007-1976  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application"s checkSuperglobals function defends against the attack.  Assigned (20070411)  None (candidate not yet proposed)    View
90869  CVE-2016-4050  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160420)  None (candidate not yet proposed)    View
25589  CVE-2007-2232  Candidate  The CHECK command in Cosign 2.0.1 and earlier allows remote attackers to bypass authentication requirements via CR ( ) sequences in the cosign cookie parameter.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 20099 of 20943, showing 5 records out of 104715 total, starting on record 100491, ending on 100495

Actions