Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Rgboard HIGH 7.5
CVE-2008-2296

PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute arbitrary PHP code via a URL …

No fix yet
Fix from $1,950 2008-05-18
Kostenloses Linkmanagementscript HIGH 7.5
CVE-2008-2270

Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,950 2008-05-16
Sr Feuser Register Extension HIGH 7.5
CVE-2008-2275

Unspecified vulnerability in sr_feuser_register 1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to 2.5.9 extension for TYPO3 allows re…

Patch available
Fix from $1,950 2008-05-16
Interact MEDIUM 6.8
CVE-2008-2220

Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow…

No fix yet
Fix from $1,600 2008-05-14
Sazcart MEDIUM 6.8
CVE-2008-2224

Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PH…

No fix yet
Fix from $1,600 2008-05-14
Cyberfolio HIGH 9.3
CVE-2008-2228

PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, all…

No fix yet
Fix from $1,950 2008-05-14
Itcms HIGH 10.0
CVE-2008-2192

Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into bo…

No fix yet
Fix from $1,950 2008-05-14
Scorpnews HIGH 7.5
CVE-2008-2193

PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execute arbitrary PHP code via a U…

No fix yet
Fix from $1,950 2008-05-14
Deluxebb MEDIUM 6.5
CVE-2008-2195

Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP cod…

Fix: after 1.2
Fix from $1,600 2008-05-14
Tellfriend MEDIUM 6.8
CVE-2008-2198

PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when register_globals is enabled, allo…

Fix: after 2.0
Fix from $1,600 2008-05-14
Kmita Mail MEDIUM 6.8
CVE-2008-2199

PHP remote file inclusion vulnerability in kmitaadmin/kmitam/htmlcode.php in Kmita Mail 3.0 and earlier, when register_globals is enabled, allows rem…

Fix: after 3.0
Fix from $1,600 2008-05-14
Office HIGH 9.3
CVE-2008-0119EPSS 31%

Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to exe…

Mitigation only
Fix from $1,950 2008-05-13
Office HIGH 9.3
CVE-2008-1091EPSS 41%

Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attacke…

Mitigation only
Fix from $1,950 2008-05-13
Windows Embedded Compact HIGH 9.3
CVE-2008-2160EPSS 18%

Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-05-12
Cms Faethon HIGH 7.5
CVE-2008-2128

PHP remote file inclusion vulnerability in templates/header.php in CMS Faethon 2.2 Ultimate allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,950 2008-05-09
Linux Kernel MEDIUM 6.9
CVE-2008-1669

Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in p…

Patch available
Fix from $1,600 2008-05-08
Harris Wap Chat HIGH 7.5
CVE-2008-2074

Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers …

No fix yet
Fix from $1,950 2008-05-05
Download Manager MEDIUM 6.8
CVE-2007-6339EPSS 11%

The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the downlo…

Fix: after 2.2.1.0
Fix from $1,600 2008-05-01
Zoneminder HIGH 7.5
CVE-2008-1381

ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary comman…

Mitigation only
Fix from $1,950 2008-05-01
Dwins HIGH 7.5
CVE-2008-2044EPSS 11%

includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, wh…

No fix yet
Fix from $1,950 2008-05-01
Egroupware HIGH 10.0
CVE-2008-2041

Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write ac…

Fix: after 1.4.003
Fix from $1,950 2008-04-30
Chicomas HIGH 7.5
CVE-2008-2016

PHP remote file inclusion vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to execute arbitrary PHP cod…

Mitigation only
Fix from $1,950 2008-04-30
Db2 HIGH 9.0
CVE-2008-1997

Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated user…

Mitigation only
Fix from $1,950 2008-04-28
123 Flash Chat Module HIGH 10.0
CVE-2008-1989

PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows rem…

No fix yet
Fix from $1,950 2008-04-27
Tr Script News MEDIUM 6.5
CVE-2008-1958

Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arb…

No fix yet
Fix from $1,600 2008-04-25
Grape Web Statistics HIGH 7.5
CVE-2008-1963EPSS 39%

PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2008-04-25
Lotus Expeditor Client HIGH 9.3
CVE-2008-1965EPSS 11%

Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus S…

No fix yet
Fix from $1,950 2008-04-25
Util Linux HIGH 7.5
CVE-2008-1926

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activi…

Mitigation only
Fix from $1,950 2008-04-24
Newsoffice HIGH 7.5
CVE-2008-1903EPSS 39%

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers …

No fix yet
Fix from $1,950 2008-04-22
Online Banking HIGH 7.5
CVE-2008-1893

PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ila…

Mitigation only
Fix from $1,950 2008-04-18