CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8560  CVE-2004-0132  Candidate  Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arbitrary PHP code from a remote web server, as demonstrated using (1) the GLOBALS[rootdp] parameter to db.php, or (2) the GLOBALS[language_home] parameter to archivednews.php, and a malicious version of lang_admin.php.  Modified (20060907)  ACCEPT(2) Armstrong, Baker | NOOP(3) Cole, Cox, Wall    View
8499  CVE-2004-0071  Candidate  Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.  Modified (20071113)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Williams | NOOP(3) Cole, Cox, Wall  Williams> contacted vendor. affects v1.2.0. fixed in v1.3.0. | http://php.amnuts.com/index.php?do=fdload&id=1&file=class.manpagelookup.php | http://php.amnuts.com/forums/viewtopic.php?t=70  View
3644  CVE-2001-0838  Candidate  Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command.  Proposed (20011122)  ACCEPT(2) Armstrong, Baker | MODIFY(1) Frech | NOOP(5) Bishop, Christey, Cole, Foat, Wall  Frech> XF:rwhoisd-remote-format-string(7353) | CONFIRM:http://www.securityfocus.com/archive/1/223080 | Christey> The CONFIRM reference by Andre is really this one: | BUGTRAQ:20011026 RWhoisd patched | URL:http://www.securityfocus.com/archive/1/223080 | Christey> CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-October/000022.html  View
4801  CVE-2002-0409  Candidate  orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.  Proposed (20020611)  ACCEPT(2) Alderson, Wall | NOOP(3) Cole, Cox, Foat | REVIEWING(1) Frech  Alderson> This is a whole new breed of exposure... vulnerable example code | leading to cross industry and application exposure. This to a point made by | Gene Kim recently "they keep deploying problems faster than we can deploy | solutions".  View
5278  CVE-2002-0888  Candidate  3Com OfficeConnect Remote 812 ADSL Router, firmware 1.1.9 and 1.1.7, allows remote attackers to bypass port access restrictions by connecting to an approved port and quickly connecting to the desired port, which is allowed by the router.  Proposed (20020830)  ACCEPT(2) Alderson, Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Jones    View

Page 20188 of 20943, showing 5 records out of 104715 total, starting on record 100936, ending on 100940

Actions