CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9743 | CVE-2004-1315 | Candidate | viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute arbitrary PHP code by double-encoding the highlight value so that special characters are inserted into the result, which is then processed by PHP exec, as exploited by the Santy.A worm. | Assigned (20041222) | None (candidate not yet proposed) | View | |
11809 | CVE-2005-0603 | Candidate | viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message. | Assigned (20050301) | None (candidate not yet proposed) | View | |
11551 | CVE-2005-0345 | Candidate | viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter. | Assigned (20050210) | None (candidate not yet proposed) | View | |
69563 | CVE-2014-2268 | Candidate | views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter. | Assigned (20140304) | None (candidate not yet proposed) | View | |
36786 | CVE-2008-6669 | Candidate | viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action. | Assigned (20090407) | None (candidate not yet proposed) | View |
Page 547 of 20943, showing 5 records out of 104715 total, starting on record 2731, ending on 2735