NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69778 | CVE-2005-4170 | SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 69779 | CVE-2005-4171 | The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 69780 | CVE-2005-4172 | eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 69781 | CVE-2005-4173 | eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 69782 | CVE-2005-4174 | eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View |
Page 2980 of 17672, showing 5 records out of 88360 total, starting on record 14896, ending on 14900