Show filters
171 Total Results
Displaying 141-150 of 171
Sort by:
Attacker Value
Unknown
CVE-2004-1723
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2004-2437
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.
0
Attacker Value
Unknown
CVE-2004-1392
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
PHP 4.0 with cURL functions allows remote attackers to bypass the open_basedir setting and read arbitrary files via a file: URL argument to the curl_init function.
0
Attacker Value
Unknown
CVE-2004-0250
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.
0
Attacker Value
Unknown
CVE-2004-0239
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.
0
Attacker Value
Unknown
CVE-2004-0269
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary SQL code and gain sensitive information via (1) the category variable in the Search module or (2) the admin variable in the Web_Links module.
0
Attacker Value
Unknown
CVE-2004-1724
Disclosure Date: August 18, 2004 (last updated February 22, 2025)
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.
0
Attacker Value
Unknown
CVE-2004-0595
Disclosure Date: July 27, 2004 (last updated February 22, 2025)
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.
0
Attacker Value
Unknown
CVE-2004-1871
Disclosure Date: March 29, 2004 (last updated February 22, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.
0
Attacker Value
Unknown
CVE-2004-1870
Disclosure Date: March 29, 2004 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.
0