Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Patbbcode MEDIUM 6.8
CVE-2007-5995

PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP …

No fix yet
Fix from $1,600 2007-11-15
Jbc Explorer MEDIUM 6.8
CVE-2007-5914EPSS 5%

Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows remote authenticated adminis…

Fix: after 7.20_rc1
Fix from $1,600 2007-11-10
Plone HIGH 7.5
CVE-2007-5741

Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects fo…

Patch available
Fix from $1,950 2007-11-07
Syndeocms MEDIUM 6.8
CVE-2007-5840

PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows remote attackers to execute arb…

No fix yet
Fix from $1,600 2007-11-06
Nuboard MEDIUM 6.8
CVE-2007-5841EPSS 31%

PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the site…

No fix yet
Fix from $1,600 2007-11-06
Vortex Portal MEDIUM 6.8
CVE-2007-5842EPSS 46%

Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary PHP code via a URL in the cfgP…

No fix yet
Fix from $1,600 2007-11-06
Scwiki MEDIUM 6.8
CVE-2007-5843EPSS 38%

PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,600 2007-11-06
Guppy HIGH 7.5
CVE-2007-5845

Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local fil…

Fix: after 4.5.16
Fix from $1,950 2007-11-06
Scribe HIGH 7.5
CVE-2007-5822

Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inject arbitrary PHP code into a …

No fix yet
Fix from $1,950 2007-11-05
Yarssr MEDIUM 6.8
CVE-2007-5837EPSS 6%

GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters i…

No fix yet
Fix from $1,600 2007-11-05
Backupwordpress Plugin MEDIUM 6.8
CVE-2007-5800EPSS 37%

Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute a…

Fix: after 0.4.2b
Fix from $1,600 2007-11-03
Flatnuke3 MEDIUM 6.0
CVE-2007-5772

Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP co…

No fix yet
Fix from $1,600 2007-11-01
Antivirus CRITICAL 9.8
CVE-2007-5775EPSS 27%

Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 2007102…

No fix yet
Fix from $2,300 2007-11-01
Teatro MEDIUM 6.8
CVE-2007-5780

PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in th…

Fix: after 1.6
Fix from $1,600 2007-11-01
Sige MEDIUM 6.8
CVE-2007-5781EPSS 39%

PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_P…

No fix yet
Fix from $1,600 2007-11-01
Emagic Cms.net HIGH 7.5
CVE-2007-5783

SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.

No fix yet
Fix from $1,950 2007-11-01
Cauposhop Pro MEDIUM 6.8
CVE-2007-5784

PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the acti…

Fix: after 2.1
Fix from $1,600 2007-11-01
Jobsite Professional HIGH 7.5
CVE-2007-5785

SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

No fix yet
Fix from $1,950 2007-11-01
Gosamba HIGH 7.5
CVE-2007-5786

Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_pat…

No fix yet
Fix from $1,950 2007-11-01
Urlinn MEDIUM 6.8
CVE-2007-5754

PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,600 2007-10-31
Japanese Php Gallery Hosting HIGH 7.5
CVE-2007-5733

Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attac…

No fix yet
Fix from $1,950 2007-10-30
Korean Ghboard HIGH 7.5
CVE-2007-5737

Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified ve…

No fix yet
Fix from $1,950 2007-10-30
Profilecms MEDIUM 6.8
CVE-2007-5720

Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via …

No fix yet
Fix from $1,600 2007-10-30
Myspace Resource Script MEDIUM 6.8
CVE-2007-5721

PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allows remote attackers to execut…

No fix yet
Fix from $1,600 2007-10-30
Jeebles Directory MEDIUM 6.0
CVE-2007-5705

Unspecified vulnerability in the Settings component in the administration system in Jeebles Directory 2.9.60 allows remote authenticated administrato…

Mitigation only
Fix from $1,600 2007-10-29
Php Image MEDIUM 6.8
CVE-2007-5697

Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the xarg parame…

No fix yet
Fix from $1,600 2007-10-29
Sitebar MEDIUM 6.0
CVE-2007-5693EPSS 5%

Eval injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP c…

Patch available
Fix from $1,600 2007-10-29
Phpbasic MEDIUM 6.8
CVE-2007-5696

PHP remote file inclusion vulnerability in includes.php in phpBasic allows remote attackers to execute arbitrary PHP code via a URL in the root param…

Mitigation only
Fix from $1,600 2007-10-29
Platinum MEDIUM 6.8
CVE-2007-5676

PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP…

No fix yet
Fix from $1,600 2007-10-24
Php Project Management MEDIUM 6.8
CVE-2007-5641EPSS 40%

Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code …

Fix: after 0.8.10
Fix from $1,600 2007-10-23