Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Odars HIGH 9.3
CVE-2008-2885

PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODA…

No fix yet
Fix from $1,950 2008-06-27
Jamroom HIGH 9.3
CVE-2008-2886

PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, a…

Patch available
Fix from $1,950 2008-06-27
Migcms HIGH 10.0
CVE-2008-2888EPSS 8%

Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2008-06-27
Cmsworks MEDIUM 6.8
CVE-2008-2877

PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is enabled, allows remote attacker…

No fix yet
Fix from $1,600 2008-06-26
Jamroom HIGH 7.5
CVE-2008-2883

PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2008-06-26
Orlando Cms HIGH 7.5
CVE-2008-2854

Multiple PHP remote file inclusion vulnerabilities in Orlando CMS 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[p…

No fix yet
Fix from $1,950 2008-06-25
Aspwebcalendar2008 HIGH 10.0
CVE-2008-2832EPSS 12%

Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arb…

No fix yet
Fix from $1,950 2008-06-24
Webcalendar HIGH 7.5
CVE-2008-2836

PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2008-06-24
Internet Explorer MEDIUM 6.8
CVE-2008-2841EPSS 15%

Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary…

Fix: after 2.8.7b
Fix from $1,600 2008-06-24
Phpraider HIGH 7.5
CVE-2008-2769

PHP remote file inclusion vulnerability in authentication/smf/smf.functions.php in Simple Machines phpRaider 1.0.6 and 1.0.7 allows remote attackers …

Mitigation only
Fix from $1,950 2008-06-18
Magic Tabs Module HIGH 7.5
CVE-2008-2772

The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly rel…

Patch available
Fix from $1,950 2008-06-18
Browsercrm HIGH 10.0
CVE-2008-2689EPSS 46%

PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2008-06-13
Browsercrm HIGH 9.3
CVE-2008-2690

Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-06-13
Black Ice Barcode Sdk HIGH 9.3
CVE-2008-2684EPSS 9%

The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long …

No fix yet
Fix from $1,950 2008-06-12
Brim HIGH 7.5
CVE-2008-2645EPSS 39%

Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $1,950 2008-06-10
Desktoponnet HIGH 7.5
CVE-2008-2649

Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_p…

No fix yet
Fix from $1,950 2008-06-10
1 Book HIGH 10.0
CVE-2008-2638

Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message …

Fix: after 1.0.1
Fix from $1,950 2008-06-10
Download Manager HIGH 9.3
CVE-2008-1770EPSS 10%

CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of…

Fix: after 2.2.3.5
Fix from $1,950 2008-06-04
Instant Support HIGH 7.5
CVE-2007-5604EPSS 12%

Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.…

Fix: after 1.0.0.23
Fix from $1,950 2008-06-04
Instant Support HIGH 7.5
CVE-2007-5607EPSS 13%

Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before …

Fix: after 1.0.0.23
Fix from $1,950 2008-06-04
Bigace HIGH 7.5
CVE-2008-2520

Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP c…

Patch available
Fix from $1,950 2008-06-03
Cpanel HIGH 8.5
CVE-2008-2478

scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to ex…

Fix: after 11.23.1
Fix from $1,950 2008-05-28
Plusphp Short Url Multi User Script HIGH 10.0
CVE-2008-2480

PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2008-05-28
Phpraider HIGH 10.0
CVE-2008-2481EPSS 5%

PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled…

No fix yet
Fix from $1,950 2008-05-28
Mambo MEDIUM 5.0
CVE-2008-2497

CRLF injection vulnerability in Mambo before 4.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attac…

Fix: after 4.6.4
Fix from $1,600 2008-05-28
Software Update MEDIUM 6.8
CVE-2008-2390EPSS 7%

Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute a…

No fix yet
Fix from $1,600 2008-05-21
Mircrossys Cms HIGH 7.5
CVE-2008-2396

PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote…

Fix: after 1.5
Fix from $1,950 2008-05-21
News Manager HIGH 7.5
CVE-2008-2341

PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the…

No fix yet
Fix from $1,950 2008-05-19
Air Filemanager HIGH 10.0
CVE-2008-2345

Unspecified vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary PHP code via unsp…

Fix: after 0.6.0
Fix from $1,950 2008-05-19
Fusebox HIGH 7.5
CVE-2008-2284

PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEB…

No fix yet
Fix from $1,950 2008-05-18