Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Simple Text File Login Script HIGH 7.5
CVE-2008-5763EPSS 39%

PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2008-12-30
Worksimple HIGH 9.3
CVE-2008-5764EPSS 45%

PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2008-12-30
Chrome MEDIUM 6.8
CVE-2008-5749

Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --render…

No fix yet
Fix from $1,600 2008-12-29
Php Collab HIGH 9.0
CVE-2008-4305

Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject a…

Fix: after 2.5
Fix from $1,950 2008-12-23
Housecall HIGH 9.3
CVE-2008-2434EPSS 7%

The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary librar…

Mitigation only
Fix from $1,950 2008-12-23
Sandbox HIGH 10.0
CVE-2008-5694

PHP remote file inclusion vulnerability in lib/jpgraph/jpgraph_errhandler.inc.php in Sandbox 1.4.1 might allow remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2008-12-19
Joomla HIGH 7.5
CVE-2008-5671

PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remo…

Fix: after 1.0.14
Fix from $1,950 2008-12-19
Webmail HIGH 10.0
CVE-2008-5619EPSS 59%

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, …

Patch available
Fix from $1,950 2008-12-17
Lcxbbportal HIGH 7.5
CVE-2008-5585

Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the p…

No fix yet
Fix from $1,950 2008-12-16
Scssboard HIGH 7.5
CVE-2008-5577

PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via …

No fix yet
Fix from $1,950 2008-12-15
Office HIGH 9.3
CVE-2008-4024EPSS 29%

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a craft…

Mitigation only
Fix from $1,950 2008-12-10
Twiki HIGH 10.0
CVE-2008-5305

Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

Fix: after 4.2.3
Fix from $1,950 2008-12-10
Jdk HIGH 9.3
CVE-2008-2086EPSS 7%

Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earl…

Fix: after 6
Fix from $1,950 2008-12-05
Pie HIGH 10.0
CVE-2008-5332

Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib paramet…

No fix yet
Fix from $1,950 2008-12-05
Nitrotech HIGH 10.0
CVE-2008-5334EPSS 9%

PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2008-12-05
Faq Manager MEDIUM 6.8
CVE-2008-5288

PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote at…

No fix yet
Fix from $1,600 2008-12-01
Phpcow HIGH 10.0
CVE-2008-5227

Unspecified vulnerability in PHPCow allows remote attackers to execute arbitrary code via unknown vectors, related to a "file inclusion vulnerability…

Mitigation only
Fix from $1,950 2008-11-25
Phpblock HIGH 9.3
CVE-2008-5210

Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_COD…

No fix yet
Fix from $1,950 2008-11-24
Ideabox HIGH 7.5
CVE-2008-5199

PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP co…

No fix yet
Fix from $1,950 2008-11-21
Mosxml HIGH 7.5
CVE-2008-5206

PHP remote file inclusion vulnerability in modules/mod_mainmenu.php in MosXML 1 Alpha allows remote attackers to execute arbitrary PHP code via a URL…

No fix yet
Fix from $1,950 2008-11-21
Orca HIGH 9.3
CVE-2008-5167

PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote at…

No fix yet
Fix from $1,950 2008-11-19
Testmaker HIGH 9.0
CVE-2008-5173

Unspecified vulnerability in testMaker before 3.0p16 allows remote authenticated users to execute arbitrary PHP code via unspecified attack vectors.

Fix: after 3.0p15
Fix from $1,950 2008-11-19
Adobe Air MEDIUM 6.8
CVE-2008-5108

Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via u…

Fix: after 1.1
Fix from $1,600 2008-11-17
Advanced Electron Forum HIGH 10.0
CVE-2008-5090

Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email…

Fix: after 1.0.6
Fix from $1,950 2008-11-14
Yoxel HIGH 9.0
CVE-2008-5071EPSS 6%

Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP …

Fix: after 1.23beta
Fix from $1,950 2008-11-14
Themesitescript HIGH 10.0
CVE-2008-5066

PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2008-11-13
Firefox MEDIUM 5.1
CVE-2008-5015

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page…

Fix: after 3.0.3
Fix from $1,600 2008-11-13
Com Rssreader HIGH 10.0
CVE-2008-5053EPSS 63%

PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attac…

No fix yet
Fix from $1,950 2008-11-13
Modernbill HIGH 10.0
CVE-2008-5060

Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in th…

Fix: after 4.4.0
Fix from $1,950 2008-11-13
Otmanager HIGH 10.0
CVE-2008-5063

PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $1,950 2008-11-13