CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27882  CVE-2007-4525  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function.  Assigned (20070824)  None (candidate not yet proposed)    View
18975  CVE-2006-2871  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. NOTE: CVE disputes this issue, since $script_path is set to a constant value.  Assigned (20060606)  None (candidate not yet proposed)    View
28471  CVE-2007-5114  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a direct request.  Assigned (20070926)  None (candidate not yet proposed)    View
28922  CVE-2007-5565  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE because the identified code is in a function that is not accessible via direct request.  Assigned (20071018)  None (candidate not yet proposed)    View
28520  CVE-2007-5163  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in includes/functions/layout.php in Nexty 1.01.A Beta allows remote attackers to execute arbitrary PHP code via a URL in the rel parameter. NOTE: this issue is disputed by CVE because the applicable include is in a function that is not called on a direct request.  Assigned (20070930)  None (candidate not yet proposed)    View

Page 46 of 20943, showing 5 records out of 104715 total, starting on record 226, ending on 230

Actions