Total
3761 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6612 | 1 Abweb | 1 Minimal-ablog | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/. | |||||
CVE-2008-6785 | 1 Galaxyscripts | 1 Mini File Host | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file. | |||||
CVE-2009-0701 | 1 Cybershade | 1 Cybershadecms | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters. | |||||
CVE-2008-6849 | 1 W2b | 1 Phpgreetcards | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a via a link that is listed by userfiles/number_shell.php. | |||||
CVE-2008-6513 | 1 Aphpkb | 1 Aphpkb | 2017-09-29 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php. | |||||
CVE-2008-6403 | 1 Openrat | 1 Openrat | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir parameter. | |||||
CVE-2008-6773 | 1 Peterselie | 1 Yourplace | 2017-09-29 | 6.5 MEDIUM | N/A |
Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary PHP code into user/internettoolbar/index.php via the (1) fav1_url, (2) fav1_name, (3) fav2_url, (4) fav2_name, (5) fav3_url, (6) fav3_name, (7) fav4_url, (8) fav4_name, (9) fav5_url, or (10) fav5_name parameters. | |||||
CVE-2008-6482 | 2 Joomla, Justjoomla | 2 Joomla, Com Treeg | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter. | |||||
CVE-2008-6518 | 1 Vidiscript | 1 Vidiscript | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request. | |||||
CVE-2009-0513 | 1 Webframe | 1 Webframe | 2017-09-29 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code via a URL in the classFiles parameter to (1) admin/doc/index.php, (2) index.php, and (3) base/menu.php in mod/. | |||||
CVE-2009-0639 | 1 Phpyabs | 1 Phpyabs | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter. | |||||
CVE-2009-0441 | 1 Technote | 1 Technote | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a different vector than CVE-2008-4138. | |||||
CVE-2008-6665 | 1 Anantasoft | 1 Ananta Cms | 2017-09-29 | 6.8 MEDIUM | N/A |
change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection. | |||||
CVE-2008-6651 | 1 Oxyproject | 1 Oxybox | 2017-09-29 | 10.0 HIGH | N/A |
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter. | |||||
CVE-2008-6287 | 1 Getmiro | 1 Broadcast Machine | 2017-09-29 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/. | |||||
CVE-2009-0595 | 1 Phpskelsite | 1 Phpskelsite | 2017-09-29 | 5.1 MEDIUM | N/A |
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter. | |||||
CVE-2009-0643 | 1 Dminnich | 1 Simple Php News | 2017-09-29 | 5.1 MEDIUM | N/A |
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6483 | 2 Joomla, Virtuemart-solutions | 2 Joomla, Com Googlebase | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |||||
CVE-2008-6539 | 1 Holger Schurig | 1 Destar | 2017-09-29 | 6.5 MEDIUM | N/A |
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter. | |||||
CVE-2008-6934 | 1 Sansuart | 1 Free Simple Guestbook Php Script | 2017-09-29 | 7.5 HIGH | N/A |
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information. |