Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Pear HIGH 7.5
CVE-2006-0144

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirect…

Patch available
Fix from $1,950 2006-01-09
Oaboard HIGH 7.5
CVE-2006-0094

PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat par…

Mitigation only
Fix from $1,950 2006-01-05
Cubecart HIGH 7.5
CVE-2006-0064

PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in…

No fix yet
Fix from $1,950 2006-01-03
Plogger HIGH 7.5
CVE-2005-4573EPSS 12%

PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in th…

Patch available
Fix from $1,950 2005-12-29
Q News HIGH 7.5
CVE-2005-3859

PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id paramet…

No fix yet
Fix from $1,950 2005-11-29
Athena Php Website Administration HIGH 7.5
CVE-2005-3860

PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2005-11-29
Phpgreetz HIGH 7.5
CVE-2005-3861

PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL …

Fix: after 0.99
Fix from $1,950 2005-11-29
Desklance HIGH 7.5
CVE-2005-3835

PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a…

Fix: after 2.3
Fix from $1,950 2005-11-26
Pollvote HIGH 7.5
CVE-2005-3775

PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname para…

Mitigation only
Fix from $1,950 2005-11-23
First4internet Xcp Drm HIGH 9.3
CVE-2005-3650EPSS 6%

The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote a…

Mitigation only
Fix from $1,950 2005-11-17
Phpkit MEDIUM 5.1
CVE-2005-3554

Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers…

No fix yet
Fix from $1,600 2005-11-16
Phpcalendar MEDIUM 5.0
CVE-2005-3571

PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and …

Fix: after 2.2
Fix from $1,600 2005-11-16
Debian Linux HIGH 7.3
CVE-2005-3302

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh fil…

No fix yet
Fix from $1,950 2005-10-24
Firefox MEDIUM 5.0
CVE-2005-2703

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and poss…

Fix: after 1.7.11
Fix from $1,600 2005-09-23
Webgui HIGH 7.5
CVE-2005-2837

Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help…

Fix: 6.7.3+
Fix from $1,950 2005-09-07
Ubuntu Linux MEDIUM 5.0
CVE-2005-1527

Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl…

Fix: after 6.4
Fix from $1,600 2005-08-15
Debian Linux HIGH 7.5
CVE-2005-2498EPSS 5%

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew,…

Fix: after 1.1.1
Fix from $1,950 2005-08-15
Xml Rpc HIGH 7.5
CVE-2005-1921EPSS 79%

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earl…

Fix: 1.8.5 / 4.5.4+
Fix from $1,950 2005-07-05
Siteframe HIGH 7.5
CVE-2005-1965

PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the L…

No fix yet
Fix from $1,950 2005-06-16
Bitrix Site Manager MEDIUM 5.0
CVE-2005-1996

PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERV…

Patch available
Fix from $1,600 2005-06-15
Flatnuke HIGH 7.5
CVE-2005-1894

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer head…

Patch available
Fix from $1,950 2005-06-09
Tell A Friend Script HIGH 7.5
CVE-2005-0679

PHP remote file inclusion vulnerability in tell_a_friend.inc.php for Tell A Friend Script 2.7 before 20050305 allows remote attackers to execute arbi…

Fix: after 2.7
Fix from $1,950 2005-05-02
Firefox HIGH 7.5
CVE-2005-1155EPSS 8%

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="i…

Patch available
Fix from $1,950 2005-05-02
Webinsta Mailing Manager HIGH 7.5
CVE-2005-0748

PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by…

Patch available
Fix from $1,950 2005-03-10
Mcnews HIGH 7.5
CVE-2005-0720

PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the …

Mitigation only
Fix from $1,950 2005-03-08
Squirrelmail HIGH 7.5
CVE-2005-0103

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifyin…

Patch available
Fix from $1,950 2005-01-24
Ie HIGH 7.5
CVE-2004-1166EPSS 39%

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via a…

No fix yet
Fix from $1,950 2004-12-31
Zeroboard MEDIUM 6.8
CVE-2004-1419

PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _z…

Patch available
Fix from $1,600 2004-12-31
Php Calendar HIGH 7.5
CVE-2004-1423EPSS 15%

Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth of Massachusetts Virtual Law O…

Fix: after 0.10
Fix from $1,950 2004-12-31
Oracle8i MEDIUM 6.5
CVE-2004-0637EPSS 18%

Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, whic…

Patch available
Fix from $1,600 2004-09-02