CVE List

Id CVE No. Status Description Phase Votes Comments Actions
20526  CVE-2006-4422  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the relative_script_path parameter, a different vector than CVE-2006-2270. NOTE: this issue has been disputed, and as of 20060830, CVE analysis concurs with the dispute. In addition, it is likely that the vulnerability is actually in a third party module, phpDig 1.8.8.  Assigned (20060828)  None (candidate not yet proposed)    View
26710  CVE-2007-3353  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in includes/template.php in MyEvent 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter. NOTE: a reliable third party disputes this issue, saying "the entire file is a class."  Assigned (20070622)  None (candidate not yet proposed)    View
25052  CVE-2007-1695  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly.  Assigned (20070326)  None (candidate not yet proposed)    View
23844  CVE-2007-0487  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used.  Assigned (20070124)  None (candidate not yet proposed)    View
23546  CVE-2007-0189  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote attackers to execute arbitrary PHP code via a URL in the action parameter. NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value.  Assigned (20070110)  None (candidate not yet proposed)    View

Page 47 of 20943, showing 5 records out of 104715 total, starting on record 231, ending on 235

Actions