Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-7136 | 1 Icq | 1 Icq Toolbar | 2017-09-29 | 4.3 MEDIUM | N/A |
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyById method, different vectors than CVE-2008-7135. | |||||
CVE-2008-7107 | 1 Eset | 1 Smart Security | 2017-09-29 | 7.2 HIGH | N/A |
easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request to the \\.\easdrv device interface. | |||||
CVE-2008-6492 | 1 Tizag | 1 Tizag Countdown Creator | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6175 | 1 K2sxs | 1 Silvershield | 2017-09-29 | 5.0 MEDIUM | N/A |
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command. | |||||
CVE-2008-6942 | 1 Scriptsfeed | 1 Realtor Classifieds System | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/. | |||||
CVE-2008-7180 | 1 Rittwick Banerjee | 1 Telephone Directory 2008 | 2017-09-29 | 5.0 MEDIUM | N/A |
del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request with a modified id variable. | |||||
CVE-2008-6938 | 1 Holger Zimmermann | 1 Pi3web | 2017-09-29 | 4.3 MEDIUM | N/A |
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt. | |||||
CVE-2009-0602 | 1 Wikkitikkitavi | 1 Wikkitikkitavi | 2017-09-29 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/. | |||||
CVE-2008-6772 | 1 Peterselie | 1 Yourplace | 2017-09-29 | 7.5 HIGH | N/A |
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a target user. | |||||
CVE-2008-6882 | 2 Joomla, Joompolitan | 2 Joomla, Com Livechat | 2017-09-29 | 7.5 HIGH | N/A |
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string. | |||||
CVE-2008-6943 | 1 Scriptsfeed | 1 Recipes Listing Portal | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/. | |||||
CVE-2008-6790 | 1 Minddezign | 1 Photo Gallery | 2017-09-29 | 5.1 MEDIUM | N/A |
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php. | |||||
CVE-2008-6826 | 1 Mhfmedia | 1 Ads Pro | 2017-09-29 | 10.0 HIGH | N/A |
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using the (1) advert_top.htm or (2) advert_login.htm pages. | |||||
CVE-2008-6538 | 1 Holger Schurig | 1 Destar | 2017-09-29 | 5.0 MEDIUM | N/A |
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser. | |||||
CVE-2008-6558 | 2 Sco, Unixware | 2 Unixware, Reliantha | 2017-09-29 | 7.2 HIGH | N/A |
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program. | |||||
CVE-2008-6367 | 1 Socialgroupie | 1 Social Groupie | 2017-09-29 | 8.5 HIGH | N/A |
Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in Member_images/. | |||||
CVE-2008-6742 | 1 Gofoxy | 1 Foxy | 2017-09-29 | 4.3 MEDIUM | N/A |
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value. | |||||
CVE-2008-6745 | 1 Blogphp | 1 Blogphp | 2017-09-29 | 7.5 HIGH | N/A |
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action. | |||||
CVE-2008-6806 | 1 7-shop | 1 7shop | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/artikel/. | |||||
CVE-2008-6751 | 1 Revou | 2 Revou, Tclone | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo. |