Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phplist MEDIUM 6.8
CVE-2011-0748

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administr…

Fix: after 2.10.12
Fix from $1,600 2011-04-13
Phplist HIGH 7.5
CVE-2009-0422EPSS 6%

Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attacker…

Fix: after 2.10.8
Fix from $1,950 2009-02-05
Phplist MEDIUM 5.0
CVE-2008-5887EPSS 11%

phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."

Fix: after 2.10.7
Fix from $1,600 2009-01-12
Webbler Cms MEDIUM 5.0
CVE-2007-4072

Webbler CMS before 3.1.6 provides the full installation path within HTML comments in certain documents, which allows remote attackers to obtain sensi…

Fix: after 3.1.4
Fix from $1,600 2007-07-30
Webbler Cms MEDIUM 5.0
CVE-2007-4073

Webbler CMS before 3.1.6 does not properly restrict use of "mail a friend" forms, which allows remote attackers to send arbitrary amounts of forged e…

Fix: after 3.1.4
Fix from $1,600 2007-07-30
Phplist HIGH 7.5
CVE-2006-5322

Multiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

Fix: after 2.10.2
Fix from $1,950 2006-10-17
Phplist MEDIUM 5.0
CVE-2006-1746

Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database…

Fix: after 2.10.2
Fix from $1,600 2006-04-12
Phplist MEDIUM 6.5
CVE-2005-3555

Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute ar…

Fix: after 2.10.1
Fix from $1,600 2005-11-16
Phplist MEDIUM 5.0
CVE-2005-3557

Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot…

Fix: after 2.10.1
Fix from $1,600 2005-11-16
Phplist HIGH 7.5
CVE-2005-2432

SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2)…

Mitigation only
Fix from $1,950 2005-08-03
Phplist MEDIUM 5.0
CVE-2005-2433

PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) us…

Mitigation only
Fix from $1,600 2005-08-03