CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23439  CVE-2007-0082  Candidate  users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.  Assigned (20070104)  None (candidate not yet proposed)    View
67269  CVE-2013-7322  Candidate  usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.  Assigned (20140209)  None (candidate not yet proposed)    View
19208  CVE-2006-3104  Candidate  users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.  Assigned (20060620)  None (candidate not yet proposed)    View
12786  CVE-2005-1580  Candidate  users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.  Assigned (20050514)  None (candidate not yet proposed)    View
2104  CVE-2000-0527  Candidate  userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.  Proposed (20000712)  ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(4) Christey, LeBlanc, Ozancin, Wall  Christey> Modify description - explicitly mention %0a string; other | metachar"s are filtered | Frech> XF:mailstudio-cgi-input-vaildation(4739)  View

Page 584 of 20943, showing 5 records out of 104715 total, starting on record 2916, ending on 2920

Actions