NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
67953  CVE-2005-2251  PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.    7.5  High  2017-07-18  2017-07-10  View
67954  CVE-2005-2252  PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.    7.5  High  2017-01-03  2008-09-05  View
67955  CVE-2005-2253  SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.    7.5  High  2017-01-03  2008-09-05  View
67956  CVE-2005-2254  Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there is evidence that viewnews.php and login.php may not be part of the PhpAuction product, so they are not included in this description.    4.3  Medium  2017-01-03  2010-12-21  View
67957  CVE-2005-2255  Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.    6.4  Medium  2017-01-03  2008-09-05  View

Page 2615 of 17672, showing 5 records out of 88360 total, starting on record 13071, ending on 13075

Actions