Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2008-3368
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to ex…
Atutor
after 1.6.1
HIGH 7.5
CVE-2008-3354
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbit…
Newbb Plus Module
No fix yet
MEDIUM 6.5
CVE-2008-3332EPSS 9%
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via th…
Mantis
after 1.1.1
HIGH 10.0
CVE-2008-3335
Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.
Punbb
after 1.2.18
MEDIUM 6.8
CVE-2008-3308
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote at…
Youtube Blog
No fix yet
HIGH 7.5
CVE-2008-3311
PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in …
Flip
No fix yet
HIGH 7.5
CVE-2008-3313
Multiple PHP remote file inclusion vulnerabilities in CreaCMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) cfg[docum…
Creacms
No fix yet
MEDIUM 6.0
CVE-2008-3298
SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PH…
Social Engine
after 2.81
HIGH 9.3
CVE-2008-3285EPSS 7%
The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell m…
Filesys Smbclientparser
Mitigation only
HIGH 9.3
CVE-2008-3246EPSS 7%
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 a…
Enterprise Server
Mitigation only
HIGH 9.3
CVE-2008-3232
Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary co…
Dotclear
after 1.2.7
HIGH 9.3
CVE-2008-3207EPSS 6%
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers t…
Praygan Cms
No fix yet
HIGH 7.5
CVE-2008-3198
Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat…
Firefox
Mitigation only
HIGH 7.5
CVE-2008-3183
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code…
Gapicms
No fix yet
HIGH 9.3
CVE-2008-3166EPSS 6%
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote atta…
Ray
No fix yet
HIGH 9.3
CVE-2008-3167EPSS 6%
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbit…
Dolphin
No fix yet
MEDIUM 6.5
CVE-2008-3093
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by …
Imperialbb
after 2.3.5
HIGH 9.3
CVE-2008-1435EPSS 29%
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted s…
Windows Nt
Mitigation only
MEDIUM 6.8
CVE-2008-2463EPSS 59%
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Offi…
Office Snapshot Viewer Activex
No fix yet
HIGH 7.5
CVE-2008-2950EPSS 14%
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constr…
Poppler
after 0.8.4
HIGH 7.5
CVE-2008-3043
Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary co…
Wec Discussion Forum
after 1.6.2
HIGH 7.5
CVE-2008-3022
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitr…
Phportal
No fix yet
HIGH 9.3
CVE-2008-3001
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrar…
Aggregation Module
Patch available
HIGH 7.5
CVE-2008-2977
Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_…
Ourvideo Cms
No fix yet
MEDIUM 6.8
CVE-2008-2981
PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows…
Homeph Design
No fix yet
HIGH 7.5
CVE-2008-2986
Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_ro…
Phpdmca
No fix yet
HIGH 7.5
CVE-2008-2990
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows re…
Com Facileforms
No fix yet
MEDIUM 6.8
CVE-2008-2905EPSS 18%
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals…
Mambo
No fix yet
HIGH 7.5
CVE-2008-2912
Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) c…
Contenido Cms
Patch available
HIGH 9.3
CVE-2008-2884
PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path …
Rss Aggregator
No fix yet