CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25333  CVE-2007-1976  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in the Virii Info 1.10 and earlier module for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter. NOTE: the issue has been disputed by a reliable third party, stating that the application"s checkSuperglobals function defends against the attack.  Assigned (20070411)  None (candidate not yet proposed)    View
20165  CVE-2006-4061  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the rep_par_rapport_racine variable is initialized before use.  Assigned (20060809)  None (candidate not yet proposed)    View
28522  CVE-2007-5165  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in init.php in Jens Tkotz myIpacNG-stats (MINGS) 0.05 allows remote attackers to execute arbitrary PHP code via a URL in the MINGS_BASE parameter. NOTE: this issue is disputed by CVE because MINGS_BASE is defined before use.  Assigned (20070930)  None (candidate not yet proposed)    View
22003  CVE-2006-5899  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter. NOTE: this issue has been disputed by a third party, who states that install.php3 is supposed to be deleted after installation and, if not deleted, intentionally allows setting repertoire without an inclusion attack.  Assigned (20061115)  None (candidate not yet proposed)    View
25668  CVE-2007-2311  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter. NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized before use.  Assigned (20070426)  None (candidate not yet proposed)    View

Page 51 of 20943, showing 5 records out of 104715 total, starting on record 251, ending on 255

Actions