CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
22765 | CVE-2006-6661 | Candidate | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters. | Assigned (20061220) | None (candidate not yet proposed) | View | |
23183 | CVE-2006-7079 | Candidate | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption["pagetype"] variable. | Assigned (20070227) | None (candidate not yet proposed) | View | |
24332 | CVE-2007-0975 | Candidate | Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array. | Assigned (20070215) | None (candidate not yet proposed) | View | |
24991 | CVE-2007-1634 | Candidate | Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation. | Assigned (20070323) | None (candidate not yet proposed) | View | |
24287 | CVE-2007-0930 | Candidate | Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP"s extract function. | Assigned (20070213) | None (candidate not yet proposed) | View |
Page 572 of 20943, showing 5 records out of 104715 total, starting on record 2856, ending on 2860