CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27740  CVE-2007-4383  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in tracking.php in Trackeur 1 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: CVE and a third party dispute this vulnerability because header is defined before use. The researcher is known to be unreliable.  Assigned (20070817)  None (candidate not yet proposed)    View
20453  CVE-2006-4349  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tcms_administer_site parameter to an unspecified script, probably index.php. NOTE: this issue has been disputed by a third party, who states that $tcms_administer_site is initialized to a constant value within index.php.  Assigned (20060824)  None (candidate not yet proposed)    View
22967  CVE-2006-6863  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value.  Assigned (20070104)  None (candidate not yet proposed)    View
18969  CVE-2006-2865  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a site-specific vulnerability, or an issue in a mod.  Assigned (20060606)  None (candidate not yet proposed)    View
19144  CVE-2006-3040  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by CVE, since the $direct variable is set to a static value just before the include statement.  Assigned (20060615)  None (candidate not yet proposed)    View

Page 20887 of 20943, showing 5 records out of 104715 total, starting on record 104431, ending on 104435

Actions