Skip to main content

Vendor/product archive

tincan / phplist CVEs

Beta · best-effort

14 CVEs tagged to tincan / phplist0 Critical, 3 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2012-5228

Published Oct 1, 2012

Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1682

Published Apr 13, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0748

Published Apr 13, 2011

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) ad…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0422

Published Feb 5, 2009

Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5887

Published Jan 12, 2009

phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5321

Published Oct 17, 2006

Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5322

Published Oct 17, 2006

Multiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5294

Published Oct 16, 2006

Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the unsubscribeemail parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1746

Published Apr 12, 2006

Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[langua…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3555

Published Nov 16, 2005

Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3556

Published Nov 16, 2005

Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3557

Published Nov 16, 2005

Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2432

Published Aug 3, 2005

SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2433

Published Aug 3, 2005

PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lis…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1