NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
69778  CVE-2005-4170  SQL injection vulnerability in eFiction 1.1 allows remote attackers to execute arbitrary SQL commands via the uid parameter to viewuser.php.    7.5  High  2017-01-03  2011-03-07  View
69779  CVE-2005-4171  The "Upload new image" command in the "Manage Images" eFiction 1.1, when members are allowed to upload images, allows remote attackers to execute arbitrary PHP code by uploading a filename with a .php extension that contains a GIF header, which passes the image validity check but executes any PHP code within the file.    7.5  High  2017-01-03  2008-09-05  View
69780  CVE-2005-4172  eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.php without arguments, which leaks the full pathname in the resulting PHP error message.    Medium  2017-01-03  2008-09-05  View
69781  CVE-2005-4173  eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which executes the PHP phpinfo function.    Medium  2017-01-03  2008-09-05  View
69782  CVE-2005-4174  eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.    7.5  High  2017-01-03  2008-09-05  View

Page 2980 of 17672, showing 5 records out of 88360 total, starting on record 14896, ending on 14900

Actions