Show filters
62 Total Results
Displaying 61-62 of 62
Sort by:
Attacker Value
Unknown
CVE-2005-2432
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.
0
Attacker Value
Unknown
CVE-2005-2433
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.
0