Show filters
116 Total Results
Displaying 101-110 of 116
Sort by:
Attacker Value
Unknown

CVE-2006-0648

Disclosure Date: February 13, 2006 (last updated February 22, 2025)
Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.
0
Attacker Value
Unknown

CVE-2005-4264

Disclosure Date: December 15, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.
0
Attacker Value
Unknown

CVE-2005-3366

Disclosure Date: October 30, 2005 (last updated February 22, 2025)
PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the original researcher.
0
Attacker Value
Unknown

CVE-2005-1404

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
0
Attacker Value
Unknown

CVE-2005-0413

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.
0
Attacker Value
Unknown

CVE-2005-1043

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
0
Attacker Value
Unknown

CVE-2004-1019

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free and negative reference index array underflow" results.
0
Attacker Value
Unknown

CVE-2004-1065

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
0
Attacker Value
Unknown

CVE-2004-0259

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.
0
Attacker Value
Unknown

CVE-2004-0595

Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
0