CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1637  CVE-2000-0059  Candidate  PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.  Proposed (20000125)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:php3-popen-execute(3900) | Christey> CONFIRM:http://www.php.net/ChangeLog.php3 | Section dated January 11, 2000 says: "Fix safe-mode problem in | popen() (Kristian)"  View
3295  CVE-2001-0478  Candidate  Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.  Proposed (20010524)  ACCEPT(2) Baker, Cole | MODIFY(1) Frech | NOOP(4) Christey, Renaud, Wall, Ziese | REVIEWING(1) Williams  Frech> XF:phpmyadmin-sqlphp-include-file(6483) | Christey> Double-check the version number - is it 2.1.0 or 2.2.0? | CONFIRM:http://phpmyadmin.sourceforge.net/ChangeLog.txt | Item 2001-04-28 says "applied security patch from [Secure | Reality] | The patch implies that tbl_replace.php was also affected.  View
3972  CVE-2001-1168  Candidate  Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.  Proposed (20020315)  ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Foat, Wall, Ziese  Frech> XF:phpmyexplorer-dot-directory-traversal(7049)  View
3660  CVE-2001-0854  Candidate  PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.  Modified (20050703)  MODIFY(1) Frech | NOOP(5) Armstrong, Bishop, Cole, Foat, Wall  Frech> XF:phpnuke-filemanager-gain-privileges(7478)  View
3113  CVE-2001-0292  Candidate  PHP-Nuke 4.4.1a allows remote attackers to modify a user"s email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.  Proposed (20010404)  ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Wall, Ziese | REVIEWING(1) Bishop  Frech> XF:phpnuke-saveuser-obtain-password(6511)  View

Page 20837 of 20943, showing 5 records out of 104715 total, starting on record 104181, ending on 104185

Actions