Show filters
62 Total Results
Displaying 61-62 of 62
Sort by:
Attacker Value
Unknown

CVE-2005-2432

Disclosure Date: August 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.
0
Attacker Value
Unknown

CVE-2005-2433

Disclosure Date: August 03, 2005 (last updated February 22, 2025)
PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.
0