Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Phpburningportal Quiz Modul HIGH 7.5
CVE-2006-7102

Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbi…

Fix: after 1.0.1
Fix from $1,950 2007-03-03
Mostlyce HIGH 7.5
CVE-2006-7104

PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for …

No fix yet
Fix from $1,950 2007-03-03
Smarty CRITICAL 9.8
CVE-2006-7105

PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $2,300 2007-03-03
Powerphlogger HIGH 7.5
CVE-2006-7106

PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code …

Fix: after 2.0.9
Fix from $1,950 2007-03-03
Awebnews MEDIUM 6.8
CVE-2007-1247

Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the pa…

No fix yet
Fix from $1,600 2007-03-03
Blender HIGH 9.3
CVE-2007-1253

Eval injection vulnerability in the (a) kmz_ImportWithMesh.py Script for Blender 0.1.9h, as used in (b) Blender before 2.43, allows user-assisted rem…

Fix: after 2.42a
Fix from $1,950 2007-03-03
Stwc Counter HIGH 7.5
CVE-2007-1233

PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attackers to execute arbitrary PHP c…

Fix: after 3.4.0
Fix from $1,950 2007-03-03
Phpbb Security MEDIUM 6.8
CVE-2006-7090

PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security 1.0.1 and earlier allows remote attackers to execute arbitrary PHP co…

Fix: after 1.0.1
Fix from $1,600 2007-03-02
Simple Plantilla Php HIGH 10.0
CVE-2007-1139

Unrestricted file upload vulnerability in Cromosoft Simple Plantilla PHP (SPP) allows remote attackers to upload arbitrary scripts via a filename wit…

No fix yet
Fix from $1,950 2007-03-02
Magic News Plus HIGH 7.5
CVE-2007-1141EPSS 6%

PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in th…

No fix yet
Fix from $1,950 2007-03-02
Hbm HIGH 7.5
CVE-2007-1147

PHP remote file inclusion vulnerability in view.php in hbm allows remote attackers to execute arbitrary PHP code via a URL in the hbmpath parameter.

Mitigation only
Fix from $1,950 2007-03-02
Lovecms HIGH 7.5
CVE-2007-1148

PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the st…

No fix yet
Fix from $1,950 2007-03-02
Cutenews HIGH 7.5
CVE-2007-1153

Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vec…

Mitigation only
Fix from $1,950 2007-03-02
Dbimagegallery HIGH 7.5
CVE-2007-1164EPSS 9%

Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the dons…

No fix yet
Fix from $1,950 2007-03-02
Dbguestbook HIGH 7.5
CVE-2007-1165

Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the dbs_base_…

No fix yet
Fix from $1,950 2007-03-02
Cm2 Network Node Manager HIGH 10.0
CVE-2007-1093

Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote atta…

Patch available
Fix from $1,950 2007-02-26
Clan Manager Pro HIGH 9.3
CVE-2006-7046

PHP remote file inclusion vulnerability in cmpro.intern/login.inc.php for Clan Manager Pro (CMPRO) 1.1.0 allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,950 2007-02-24
Flashgamescript HIGH 7.5
CVE-2007-1078

PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the …

No fix yet
Fix from $1,950 2007-02-22
Mediawiki MEDIUM 6.8
CVE-2007-1055

Cross-site scripting (XSS) vulnerability in the AJAX features in index.php in MediaWiki 1.9.x before 1.9.0rc2, and 1.8.2 and earlier allows remote at…

Fix: after 1.8.2
Fix from $1,600 2007-02-21
At Contenator MEDIUM 6.8
CVE-2007-0983

PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via …

Fix: after 1.0
Fix from $1,600 2007-02-16
Jupiter Cms MEDIUM 5.1
CVE-2007-0986

PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitr…

No fix yet
Fix from $1,600 2007-02-16
Plume Cms HIGH 7.5
CVE-2006-7021

PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code …

No fix yet
Fix from $1,950 2007-02-15
Office HIGH 9.3
CVE-2007-0209EPSS 29%

Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers t…

Mitigation only
Fix from $1,950 2007-02-13
Visual Studio .net HIGH 9.3
CVE-2007-0025EPSS 37%

The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted …

Mitigation only
Fix from $1,950 2007-02-13
Gnopaste MEDIUM 6.8
CVE-2007-0862

PHP remote file inclusion vulnerability in index.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via the GNP_…

Fix: after 0.5.3
Fix from $1,600 2007-02-09
Webhost Manager HIGH 7.5
CVE-2007-0854EPSS 6%

Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL …

No fix yet
Fix from $1,950 2007-02-08
Centipaid CRITICAL 9.8
CVE-2006-6975

PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a URL in the …

Mitigation only
Fix from $2,300 2007-02-08
Centipaid HIGH 7.5
CVE-2006-6976

PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to execute arbitrary code via a…

Fix: after 1.4.2
Fix from $1,950 2007-02-08
Atsphp HIGH 7.5
CVE-2007-0831

Multiple PHP remote file inclusion vulnerabilities in Atsphp 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the CONF[path] p…

Mitigation only
Fix from $1,950 2007-02-07
Portail Web Php HIGH 7.5
CVE-2007-0699

PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1…

Fix: after 2.5.1
Fix from $1,950 2007-02-04