
CVE-2005-3556 – PHPList Mailing List Manager 2.x - '/admin/configure.php?id' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-3556
16 Nov 2005 — Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c) admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) ac... • https://www.exploit-db.com/exploits/26484 •

CVE-2005-3557
https://notcve.org/view.php?id=CVE-2005-3557
16 Nov 2005 — Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request. • http://osvdb.org/20569 •

CVE-2005-2432 – phpList 2.8.12 - Admin Page SQL Injection
https://notcve.org/view.php?id=CVE-2005-2432
03 Aug 2005 — SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin. Vulerabilidad de inyección de SQL en PhpList permite que atacantes remotos modifiquen sentencias SQL mediante el argumento id en las páginas de administració, tales como "members" o "admin". • https://www.exploit-db.com/exploits/26045 •

CVE-2005-2433
https://notcve.org/view.php?id=CVE-2005-2433
03 Aug 2005 — PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which r... • http://marc.info/?l=bugtraq&m=112258115325054&w=2 •