CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24409  CVE-2007-1052  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in PBLang (PBL) 4.60 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbpath parameter, a different vector than CVE-2006-5062. NOTE: this issue has been disputed by a reliable third party for 4.65, stating that the dbpath variable is initialized in an included file that is created upon installation.  Assigned (20070221)  None (candidate not yet proposed)    View
23407  CVE-2007-0050  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter. NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small time window of risk before the installation is complete.  Assigned (20070103)  None (candidate not yet proposed)    View
21201  CVE-2006-5097  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in net2ftp, possibly 0.1 through 0.62, allows remote attackers to execute arbitrary PHP code via a URL in the application_rootdir parameter. NOTE: this issue has been disputed by a third party researcher, CVE, and the vendor. The vendor says "the variable is set in settings.inc.php, so this is not a vulnerability."  Assigned (20060929)  None (candidate not yet proposed)    View
23617  CVE-2007-0260  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter. NOTE: a reliable third party disputes this vulnerability because this_path is defined before use.  Assigned (20070116)  None (candidate not yet proposed)    View
21199  CVE-2006-5095  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before being used when the product is installed according to the provided instructions.  Assigned (20060929)  None (candidate not yet proposed)    View

Page 20895 of 20943, showing 5 records out of 104715 total, starting on record 104471, ending on 104475

Actions