Page 2 of 14 results (0.001 seconds)

CVSS: 4.8EPSS: 4%CPEs: 1EXPL: 4

16 Nov 2005 — Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c) admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) ac... • https://www.exploit-db.com/exploits/26484 •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 1

16 Nov 2005 — Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request. • http://osvdb.org/20569 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

03 Aug 2005 — SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin. Vulerabilidad de inyección de SQL en PhpList permite que atacantes remotos modifiquen sentencias SQL mediante el argumento id en las páginas de administració, tales como "members" o "admin". • https://www.exploit-db.com/exploits/26045 •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 0

03 Aug 2005 — PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which r... • http://marc.info/?l=bugtraq&m=112258115325054&w=2 •