Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Atutor MEDIUM 6.5
CVE-2008-3368

PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to ex…

Fix: after 1.6.1
Fix from $1,600 2008-07-30
Newbb Plus Module HIGH 7.5
CVE-2008-3354

Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbit…

No fix yet
Fix from $1,950 2008-07-28
Mantis MEDIUM 6.5
CVE-2008-3332EPSS 9%

Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via th…

Fix: after 1.1.1
Fix from $1,600 2008-07-27
Punbb HIGH 10.0
CVE-2008-3335

Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.

Fix: after 1.2.18
Fix from $1,950 2008-07-27
Youtube Blog MEDIUM 6.8
CVE-2008-3308

PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote at…

No fix yet
Fix from $1,600 2008-07-25
Flip HIGH 7.5
CVE-2008-3311

PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2008-07-25
Creacms HIGH 7.5
CVE-2008-3313

Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[docum…

No fix yet
Fix from $1,950 2008-07-25
Social Engine MEDIUM 6.0
CVE-2008-3298

SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PH…

Fix: after 2.81
Fix from $1,600 2008-07-25
Filesys Smbclientparser HIGH 9.3
CVE-2008-3285EPSS 7%

The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell m…

Mitigation only
Fix from $1,950 2008-07-24
Enterprise Server HIGH 9.3
CVE-2008-3246EPSS 7%

Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 a…

Mitigation only
Fix from $1,950 2008-07-21
Dotclear HIGH 9.3
CVE-2008-3232

Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary co…

Fix: after 1.2.7
Fix from $1,950 2008-07-18
Praygan Cms HIGH 9.3
CVE-2008-3207EPSS 6%

PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers t…

No fix yet
Fix from $1,950 2008-07-18
Firefox HIGH 7.5
CVE-2008-3198

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat…

Mitigation only
Fix from $1,950 2008-07-17
Gapicms HIGH 7.5
CVE-2008-3183

PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code…

No fix yet
Fix from $1,950 2008-07-15
Ray HIGH 9.3
CVE-2008-3166EPSS 6%

PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote atta…

No fix yet
Fix from $1,950 2008-07-14
Dolphin HIGH 9.3
CVE-2008-3167EPSS 6%

Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbit…

No fix yet
Fix from $1,950 2008-07-14
Imperialbb MEDIUM 6.5
CVE-2008-3093

Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by …

Fix: after 2.3.5
Fix from $1,600 2008-07-09
Windows Nt HIGH 9.3
CVE-2008-1435EPSS 29%

Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted s…

Mitigation only
Fix from $1,950 2008-07-08
Office Snapshot Viewer Activex MEDIUM 6.8
CVE-2008-2463EPSS 59%

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offi…

No fix yet
Fix from $1,600 2008-07-07
Poppler HIGH 7.5
CVE-2008-2950EPSS 14%

The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constr…

Fix: after 0.8.4
Fix from $1,950 2008-07-07
Wec Discussion Forum HIGH 7.5
CVE-2008-3043

Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary co…

Fix: after 1.6.2
Fix from $1,950 2008-07-07
Phportal HIGH 7.5
CVE-2008-3022

Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitr…

No fix yet
Fix from $1,950 2008-07-07
Aggregation Module HIGH 9.3
CVE-2008-3001

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrar…

Patch available
Fix from $1,950 2008-07-03
Ourvideo Cms HIGH 7.5
CVE-2008-2977

Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_…

No fix yet
Fix from $1,950 2008-07-02
Homeph Design MEDIUM 6.8
CVE-2008-2981

PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows…

No fix yet
Fix from $1,600 2008-07-02
Phpdmca HIGH 7.5
CVE-2008-2986

Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_ro…

No fix yet
Fix from $1,950 2008-07-02
Com Facileforms HIGH 7.5
CVE-2008-2990

PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows re…

No fix yet
Fix from $1,950 2008-07-02
Mambo MEDIUM 6.8
CVE-2008-2905EPSS 18%

PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals…

No fix yet
Fix from $1,600 2008-06-30
Contenido Cms HIGH 7.5
CVE-2008-2912

Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) c…

Patch available
Fix from $1,950 2008-06-30
Rss Aggregator HIGH 9.3
CVE-2008-2884

PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path …

No fix yet
Fix from $1,950 2008-06-27