Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-4493 | 1 Microsoft | 1 Digital Image | 2017-09-29 | 6.8 MEDIUM | N/A |
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. | |||||
CVE-2008-5963 | 1 Gravity-gtd | 1 Gravity-gtd | 2017-09-29 | 10.0 HIGH | N/A |
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter. | |||||
CVE-2008-5966 | 1 Globsy | 1 Globsy | 2017-09-29 | 7.5 HIGH | N/A |
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter. | |||||
CVE-2008-6084 | 1 .matteoiammarrone | 1 Iamma Simple Gallery | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory. | |||||
CVE-2008-4366 | 1 Camera Life | 1 Camera Life | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a user directory under images/photos/upload. | |||||
CVE-2008-4919 | 1 Visagesoft | 1 Expert Pdf Viewer Activex | 2017-09-29 | 8.8 HIGH | N/A |
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method. | |||||
CVE-2008-4748 | 1 Kvirc | 1 Kvirc | 2017-09-29 | 7.6 HIGH | N/A |
Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the irc:// URI. | |||||
CVE-2008-5663 | 1 Kusaba | 1 Kusaba | 2017-09-29 | 9.0 HIGH | N/A |
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory. | |||||
CVE-2008-4329 | 1 Openengine | 1 Openengine | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter. | |||||
CVE-2008-5220 | 1 Wportfolio | 1 Wportfolio | 2017-09-29 | 10.0 HIGH | N/A |
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in admin/tmp/. | |||||
CVE-2008-4509 | 1 Foss Gallery | 1 Foss Gallery | 2017-09-29 | 10.0 HIGH | N/A |
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory. | |||||
CVE-2008-3210 | 1 Resiprocate | 1 Resiprocate | 2017-09-29 | 5.0 MEDIUM | N/A |
rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error. | |||||
CVE-2008-4050 | 1 Friendly Technologies | 1 Friendly Pppoe Client | 2017-09-29 | 9.3 HIGH | N/A |
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method. | |||||
CVE-2008-4049 | 1 Friendly Technologies | 1 Friendly Pppoe Client | 2017-09-29 | 6.8 MEDIUM | N/A |
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method. | |||||
CVE-2008-3362 | 2 Giulio Ganci, Wordpress | 2 Wp Downloads Manager, Wp Downloads Manager | 2017-09-29 | 10.0 HIGH | N/A |
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/. | |||||
CVE-2008-3493 | 1 Realvnc | 1 Realvnc Windows Client | 2017-09-29 | 5.0 MEDIUM | N/A |
vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet. | |||||
CVE-2008-3811 | 1 Cisco | 1 Ios | 2017-09-29 | 7.8 HIGH | N/A |
Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability than CVE-2008-3810. | |||||
CVE-2008-3127 | 1 Hiox India | 1 Banner Rotator | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter. | |||||
CVE-2008-2742 | 1 Achievo | 1 Achievo | 2017-09-29 | 7.5 HIGH | N/A |
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled. | |||||
CVE-2008-3810 | 1 Cisco | 1 Ios | 2017-09-29 | 7.8 HIGH | N/A |
Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka CSCsg22426, a different vulnerability than CVE-2008-3811. |