Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Lama Software MEDIUM 6.8
CVE-2008-0423EPSS 37%

Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[cla…

No fix yet
Fix from $1,600 2008-01-23
Phpautovideo HIGH 7.5
CVE-2008-0433

PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers …

Fix: after 2.21
Fix from $1,950 2008-01-23
Auracms HIGH 7.5
CVE-2008-0390

stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forw…

No fix yet
Fix from $1,950 2008-01-23
Small Axe Weblog MEDIUM 6.8
CVE-2008-0376EPSS 32%

PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL …

No fix yet
Fix from $1,600 2008-01-22
Mybulletinboard HIGH 7.5
CVE-2008-0382EPSS 42%

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) f…

No fix yet
Fix from $1,950 2008-01-22
Apt Listchanges HIGH 7.2
CVE-2008-0302

Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious…

Fix: after 2.81
Fix from $1,950 2008-01-17
Vcart MEDIUM 6.8
CVE-2008-0287

PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path pa…

No fix yet
Fix from $1,600 2008-01-16
Member Area System MEDIUM 6.8
CVE-2008-0289

PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbit…

Fix: after 1.7
Fix from $1,600 2008-01-16
Domphp MEDIUM 6.8
CVE-2008-0283

PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a UR…

Fix: after 0.81
Fix from $1,600 2008-01-15
Photopost Vbgallery HIGH 10.0
CVE-2008-0251

Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown …

Fix: after 2.4.1
Fix from $1,950 2008-01-12
Vfp Ole Server Activex Control HIGH 10.0
CVE-2008-0235EPSS 29%

The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.

No fix yet
Fix from $1,950 2008-01-11
Osdate HIGH 7.5
CVE-2008-0230

PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PH…

No fix yet
Fix from $1,950 2008-01-11
Filemanager HIGH 7.5
CVE-2008-0222EPSS 8%

Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex…

No fix yet
Fix from $1,950 2008-01-10
Sam Broadcaster HIGH 7.5
CVE-2008-0143EPSS 6%

PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote att…

No fix yet
Fix from $1,950 2008-01-08
Matpo Bilder Galerie HIGH 7.5
CVE-2007-6649EPSS 6%

PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,950 2008-01-04
Xcms HIGH 7.5
CVE-2007-6652

cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code …

Fix: after 1.83
Fix from $1,950 2008-01-04
Kontakt Formular HIGH 7.5
CVE-2007-6655

PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a …

No fix yet
Fix from $1,950 2008-01-04
Multi Host HIGH 7.5
CVE-2007-6657EPSS 6%

PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to e…

No fix yet
Fix from $1,950 2008-01-04
Xml2owl MEDIUM 6.8
CVE-2007-6632

showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter.

No fix yet
Fix from $1,600 2008-01-04
Phpautovideo MEDIUM 6.8
CVE-2007-6614EPSS 6%

PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary P…

Patch available
Fix from $1,600 2008-01-03
Phpautovideo MEDIUM 6.8
CVE-2007-6615EPSS 5%

Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary lo…

Patch available
Fix from $1,600 2008-01-03
Xzero Community Classifieds HIGH 7.5
CVE-2007-6568

PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbit…

Fix: after 4.95.11
Fix from $1,950 2007-12-28
Nmnnewsletter MEDIUM 6.8
CVE-2007-6585

PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,600 2007-12-28
Runcms HIGH 7.5
CVE-2007-6548EPSS 8%

Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators to inject arbitrary PHP code v…

Fix: after 1.6
Fix from $1,950 2007-12-28
Pmos Helpdesk HIGH 7.5
CVE-2007-6550EPSS 7%

form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injec…

Fix: after 2.4
Fix from $1,950 2007-12-28
Teamcal Pro MEDIUM 6.8
CVE-2007-6553

Multiple PHP remote file inclusion vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to execute arbitrary PHP code via a URL …

Fix: after 3.1.000
Fix from $1,600 2007-12-28
Mosdirectory HIGH 9.3
CVE-2007-6555EPSS 6%

PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote a…

No fix yet
Fix from $1,950 2007-12-28
Isupport MEDIUM 6.8
CVE-2007-6539

PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local files via the include_file para…

No fix yet
Fix from $1,600 2007-12-27
Arcadem HIGH 7.5
CVE-2007-6542EPSS 6%

PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP …

Fix: after 2.04
Fix from $1,950 2007-12-27
Sitescape Forum St HIGH 7.5
CVE-2007-6515EPSS 8%

support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string.

Patch available
Fix from $1,950 2007-12-21