Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Lokicms HIGH 9.3
CVE-2008-1860

Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Conf…

Fix: after 0.3.3
Fix from $1,950 2008-04-17
Exbb Italia MEDIUM 6.8
CVE-2008-1862

ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypa…

Fix: after 0.2.2
Fix from $1,600 2008-04-17
Pixel Motion Blog HIGH 9.0
CVE-2008-1866EPSS 5%

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to uploa…

No fix yet
Fix from $1,950 2008-04-17
Visualpic MEDIUM 6.8
CVE-2008-1876EPSS 25%

PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the _CONFI…

No fix yet
Fix from $1,600 2008-04-17
Arcserve Backup Laptops And Desktops HIGH 9.3
CVE-2008-1786EPSS 7%

The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktop…

Patch available
Fix from $1,950 2008-04-16
Dragoon MEDIUM 6.8
CVE-2008-1773EPSS 24%

PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,600 2008-04-14
Phpblock MEDIUM 6.8
CVE-2008-1776EPSS 24%

PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,600 2008-04-14
Blogator Script MEDIUM 6.8
CVE-2008-1760

Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a URL in t…

Fix: after 1.00
Fix from $1,600 2008-04-12
Mxbb HIGH 7.5
CVE-2008-1712

PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,950 2008-04-09
Windows 2000 HIGH 9.3
CVE-2008-0083EPSS 30%

The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Serve…

Patch available
Fix from $1,950 2008-04-08
Windows 2000 HIGH 7.2
CVE-2008-1084EPSS 7%

Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows loc…

Patch available
Fix from $1,950 2008-04-08
Ie HIGH 9.3
CVE-2008-1085EPSS 32%

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a cr…

Patch available
Fix from $1,950 2008-04-08
Internet Explorer HIGH 9.3
CVE-2008-1086EPSS 31%

The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vist…

Patch available
Fix from $1,950 2008-04-08
Office HIGH 9.3
CVE-2008-1089EPSS 32%

Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrar…

Patch available
Fix from $1,950 2008-04-08
Online Flashquiz MEDIUM 6.8
CVE-2008-1682EPSS 24%

PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! al…

No fix yet
Fix from $1,600 2008-04-04
Installshield HIGH 9.3
CVE-2007-5661

The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as…

Fix: 12+
Fix from $1,950 2008-04-04
Geecarts MEDIUM 6.8
CVE-2008-1622

Multiple PHP remote file inclusion vulnerabilities in GeeCarts allow remote attackers to execute arbitrary PHP code via a URL in the id parameter to …

Mitigation only
Fix from $1,600 2008-04-02
Jaf Cms MEDIUM 6.8
CVE-2008-1609EPSS 41%

Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code v…

No fix yet
Fix from $1,600 2008-04-01
Firefox MEDIUM 6.8
CVE-2008-1233

Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to exec…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Oocomments CRITICAL 9.8
CVE-2008-1511

Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComm…

No fix yet
Fix from $2,300 2008-03-25
Custompages HIGH 7.5
CVE-2008-1505EPSS 46%

PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers …

Fix: after 1.1
Fix from $1,950 2008-03-25
W Agora HIGH 7.5
CVE-2008-1466

Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_defaul…

No fix yet
Fix from $1,950 2008-03-24
Centerim MEDIUM 6.8
CVE-2008-1467

CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "receiv…

No fix yet
Fix from $1,600 2008-03-24
Flash MEDIUM 6.8
CVE-2008-1201EPSS 20%

Multiple unspecified vulnerabilities in FLA file parsing in Adobe Flash CS3 Professional, Flash Professional 8, and Flash Basic 8 on Windows allow us…

Mitigation only
Fix from $1,600 2008-03-24
Fuzzylime MEDIUM 6.8
CVE-2008-1405EPSS 35%

PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,600 2008-03-20
Phpauction Gpl MEDIUM 6.8
CVE-2008-1416EPSS 35%

Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the inclu…

No fix yet
Fix from $1,600 2008-03-20
Mac Os X MEDIUM 6.8
CVE-2008-0060

Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML…

Patch available
Fix from $1,600 2008-03-18
Yap Blog MEDIUM 6.8
CVE-2008-1370

PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,600 2008-03-18
Biztalk Server HIGH 9.3
CVE-2007-1201EPSS 29%

Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary c…

Patch available
Fix from $1,950 2008-03-11
Office HIGH 9.3
CVE-2008-0110EPSS 32%

Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers …

Patch available
Fix from $1,950 2008-03-11