Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Extcalendar MEDIUM 6.8
CVE-2006-3556EPSS 7%

PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code v…

No fix yet
Fix from $1,600 2006-07-13
Pc Cookbook MEDIUM 6.8
CVE-2006-3530EPSS 6%

PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.…

No fix yet
Fix from $1,600 2006-07-12
Simpleboard MEDIUM 6.8
CVE-2006-3528

Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code…

Fix: after 1.1.0
Fix from $1,600 2006-07-12
Office HIGH 9.3
CVE-2006-1316EPSS 15%

Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to…

Mitigation only
Fix from $1,950 2006-07-11
Office HIGH 9.3
CVE-2006-2389EPSS 39%

Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to…

Mitigation only
Fix from $1,950 2006-07-11
Sitebuilder Fx MEDIUM 5.1
CVE-2006-3395

PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admin…

No fix yet
Fix from $1,600 2006-07-06
Galleria MEDIUM 6.8
CVE-2006-3396

PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute ar…

No fix yet
Fix from $1,600 2006-07-06
Ralf Image Gallery MEDIUM 5.1
CVE-2006-3210EPSS 14%

Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file in…

Patch available
Fix from $1,600 2006-06-24
Content\*builder HIGH 7.5
CVE-2006-3172EPSS 16%

Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a tra…

No fix yet
Fix from $1,950 2006-06-23
Mcguestbook HIGH 7.5
CVE-2006-3175EPSS 9%

Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang para…

Mitigation only
Fix from $1,950 2006-06-23
Bandsite Cms MEDIUM 5.1
CVE-2006-3193EPSS 15%

Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execu…

No fix yet
Fix from $1,600 2006-06-23
Nucleus Cms CRITICAL 9.8
CVE-2006-3136

Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parame…

No fix yet
Fix from $2,300 2006-06-22
Micro Cms HIGH 7.5
CVE-2006-3144EPSS 9%

PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allo…

No fix yet
Fix from $1,950 2006-06-22
Phpcms HIGH 7.5
CVE-2006-3019EPSS 8%

Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_IN…

Mitigation only
Fix from $1,950 2006-06-15
Ie HIGH 9.3
CVE-2006-1303EPSS 38%

Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code b…

Patch available
Fix from $1,950 2006-06-13
Ie HIGH 7.6
CVE-2006-2385EPSS 20%

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2006-06-13
Dotwidget Cms MEDIUM 6.8
CVE-2006-2852EPSS 11%

PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbi…

No fix yet
Fix from $1,600 2006-06-06
Webspotblogging MEDIUM 6.4
CVE-2006-2860EPSS 13%

PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path paramete…

No fix yet
Fix from $1,600 2006-06-06
Firefox HIGH 9.3
CVE-2006-2779EPSS 7%

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1…

Patch available
Fix from $1,950 2006-06-02
Firefox HIGH 9.3
CVE-2006-2780EPSS 7%

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute …

Fix: after 1.5.0.3
Fix from $1,950 2006-06-02
Ottoman MEDIUM 5.1
CVE-2006-2767

PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via…

No fix yet
Fix from $1,600 2006-06-02
Socketmail MEDIUM 6.8
CVE-2006-2681

PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remo…

Fix: after 2.2.6
Fix from $1,600 2006-05-31
Actionapps MEDIUM 6.4
CVE-2006-2686EPSS 14%

PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PA…

No fix yet
Fix from $1,600 2006-05-31
Plume Cms HIGH 7.5
CVE-2006-2645EPSS 6%

PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execute arbitrary code via a URL i…

No fix yet
Fix from $1,950 2006-05-30
Perlpodder HIGH 7.5
CVE-2006-2548EPSS 13%

Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (ur…

Fix: after 0.4
Fix from $1,950 2006-05-23
Phpmydirectory HIGH 7.5
CVE-2006-2521

PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to execute arbitrary PHP code via a …

Fix: after 10.4.4
Fix from $1,950 2006-05-22
Popphoto MEDIUM 5.0
CVE-2006-2395

PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows …

Mitigation only
Fix from $1,600 2006-05-16
Ispconfig HIGH 7.5
CVE-2006-2315

PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a…

Fix: after 2.2.2
Fix from $1,950 2006-05-12
X Poll HIGH 7.5
CVE-2006-2281

X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute arbitrary PHP code by using admin/images/add.php to upload a PHP file, then access i…

No fix yet
Fix from $1,950 2006-05-10
Dokeos MEDIUM 6.8
CVE-2006-2286

Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allo…

Fix: after 1.6.3
Fix from $1,600 2006-05-10