Show filters
36 Total Results
Displaying 31-36 of 36
Sort by:
Attacker Value
Unknown
CVE-2005-3557
Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.
0
Attacker Value
Unknown
CVE-2005-2432
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.
0
Attacker Value
Unknown
CVE-2005-2433
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.
0
Attacker Value
Unknown
CVE-2005-1750
Disclosure Date: May 25, 2005 (last updated February 22, 2025)
SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
0
Attacker Value
Unknown
CVE-2002-1755
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.
0
Attacker Value
Unknown
CVE-2001-1505
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.
0