Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2004-1926EPSS 7%

Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4…

Fix: after 1.8.1
Fix from $1,950 2004-04-11
Gallery HIGH 7.5
CVE-2003-1227EPSS 7%

PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remo…

Patch available
Fix from $1,950 2003-12-31
Cutenews HIGH 7.5
CVE-2003-1240EPSS 7%

PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in…

No fix yet
Fix from $1,950 2003-12-31
Bookmark4u HIGH 7.5
CVE-2003-1253

PHP remote file inclusion vulnerability in Bookmark4U 1.8.3 allows remote attackers to execute arbitrary PHP code viaa URL in the prefix parameter to…

No fix yet
Fix from $1,950 2003-12-31
Invision Power Board MEDIUM 6.8
CVE-2003-1385

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root…

No fix yet
Fix from $1,600 2003-12-31
D Forum HIGH 7.5
CVE-2003-1406

PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_he…

No fix yet
Fix from $1,950 2003-12-31
Cedric Email Reader MEDIUM 6.8
CVE-2003-1410

PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote attackers to execute arbitrary…

No fix yet
Fix from $1,600 2003-12-31
Cedric Email Reader MEDIUM 6.8
CVE-2003-1411

PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows remote attackers to execute arb…

No fix yet
Fix from $1,600 2003-12-31
Gonicus System Administration MEDIUM 6.8
CVE-2003-1412

PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP cod…

No fix yet
Fix from $1,600 2003-12-31
Unreal Engine HIGH 10.0
CVE-2003-1432EPSS 8%

Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitr…

No fix yet
Fix from $1,950 2003-12-31
Nukebrowser MEDIUM 6.8
CVE-2003-1436

PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute arbitrary PHP code via the fi…

Patch available
Fix from $1,600 2003-12-31
Ttcms MEDIUM 6.8
CVE-2003-1459EPSS 7%

Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template…

No fix yet
Fix from $1,600 2003-12-31
Personal Firewall HIGH 7.5
CVE-2003-1491

Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the…

Mitigation only
Fix from $1,950 2003-12-31
Cpcommerce MEDIUM 6.8
CVE-2003-1500

PHP remote file inclusion vulnerability in _functions.php in cpCommerce 0.5f allows remote attackers to execute arbitrary code via the prefix paramet…

Mitigation only
Fix from $1,600 2003-12-31
Cache Database HIGH 7.2
CVE-2003-0498

Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding serve…

Mitigation only
Fix from $1,950 2003-08-07
Ultimate Php Board HIGH 7.5
CVE-2003-0395

Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing t…

Mitigation only
Fix from $1,950 2003-07-02
Csguestbook HIGH 7.5
CVE-2002-1750

csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed b…

Mitigation only
Fix from $1,950 2002-12-31
Cschat R Box HIGH 7.5
CVE-2002-1752

csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by th…

Mitigation only
Fix from $1,950 2002-12-31
Csnews Professional HIGH 7.5
CVE-2002-1753EPSS 32%

csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which …

Mitigation only
Fix from $1,950 2002-12-31
Oscommerce HIGH 7.5
CVE-2002-1991EPSS 7%

PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_once.php.

No fix yet
Fix from $1,950 2002-12-31
Oscommerce HIGH 7.5
CVE-2002-2019

PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2002-12-31
News Evolution HIGH 7.5
CVE-2002-2249

PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1…

No fix yet
Fix from $1,950 2002-12-31
Advanced Quick Reply Hack HIGH 7.5
CVE-2002-2287

PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2002-12-31
Thatware MEDIUM 6.8
CVE-2002-2297

PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root…

No fix yet
Fix from $1,600 2002-12-31
Thatware MEDIUM 6.8
CVE-2002-2298

PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the roo…

Fix: after 0.5.3
Fix from $1,600 2002-12-31
Thatware MEDIUM 6.8
CVE-2002-2299

PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the r…

Fix: after 0.5.2
Fix from $1,600 2002-12-31
Mysimplenews HIGH 7.5
CVE-2002-2319

Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2)…

No fix yet
Fix from $1,950 2002-12-31
Cssearch Professional HIGH 10.0
CVE-2002-0495EPSS 13%

csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, wh…

Fix: after 2.3
Fix from $1,950 2002-08-12
Java Http Server HIGH 7.5
CVE-2001-0307EPSS 8%

Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP re…

Fix: after 0.79
Fix from $1,950 2001-05-03
Java Http Server HIGH 7.5
CVE-2001-0308

UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling t…

Fix: after 0.79
Fix from $1,950 2001-05-03