Total
3761 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-0300 | 1 Mapbender | 1 Mapbender | 2017-09-29 | 6.8 MEDIUM | N/A |
mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences. | |||||
CVE-2008-1405 | 1 Fuzzylime | 1 Fuzzylime | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter. | |||||
CVE-2007-6585 | 1 Nmnnewsletter | 1 Nmnnewsletter | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter. | |||||
CVE-2008-1038 | 1 Drbenhur.com | 1 Dbhcms | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the extmanager_install parameter. | |||||
CVE-2008-1067 | 1 Phpqladmin | 1 Phpqladmin | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[path] parameter to (1) ezmlm.php and (2) tools/update_translations.php. | |||||
CVE-2008-1876 | 1 Snarky | 1 Visualpic | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[files][functions_page] parameter. | |||||
CVE-2008-1074 | 1 Group E | 1 Group E | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[PREPEND_FILE] parameter. | |||||
CVE-2007-6632 | 1 Xml2owl | 1 Xml2owl | 2017-09-29 | 6.8 MEDIUM | N/A |
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter. | |||||
CVE-2008-1416 | 1 Phpauction | 1 Phpauction Gpl | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/. | |||||
CVE-2008-1124 | 1 Podcast Generator | 1 Podcast Generator | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3) categories.php, (4) categories_add.php, (5) categories_remove.php, (6) edit.php, (7) editdel.php, (8) ftpfeature.php, (9) login.php, (10) pgRSSnews.php, (11) showcat.php, and (12) upload.php in core/admin/; and (13) archive_cat.php, (14) archive_nocat.php, and (15) recent_list.php in core/. | |||||
CVE-2008-1862 | 1 Exbb | 1 Exbb Italia | 2017-09-29 | 6.8 MEDIUM | N/A |
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or (2) COOKIE variables, a different vector than CVE-2006-4488. NOTE: this can be leveraged to conduct PHP remote file inclusion attacks via a URL in the (a) new_exbb[home_path] or (b) exbb[home_path] parameter to modules/threadstop/threadstop.php. | |||||
CVE-2008-1866 | 1 Pixel Motion | 1 Pixel Motion Blog | 2017-09-29 | 9.0 HIGH | N/A |
admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request. | |||||
CVE-2008-1903 | 1 Newanz | 1 Newsoffice | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter. | |||||
CVE-2008-1958 | 1 Easyscripts | 1 Tr Script News | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension. | |||||
CVE-2008-1069 | 1 Quantum Game Library | 1 Quantum Game Library | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) server_request.php and (2) qlib/smarty.inc.php. | |||||
CVE-2008-0376 | 1 Softpedia | 1 Small Axe Weblog | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter. | |||||
CVE-2008-0283 | 1 Domphp | 1 Domphp | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |||||
CVE-2008-0567 | 1 Chronoengine | 1 Chronoforms | 2017-09-29 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/; and (4) BIFFwriter.php, (5) Workbook.php, (6) Worksheet.php, and (7) Format.php in excelwriter/Writer/. | |||||
CVE-2008-0503 | 1 Netwerk | 1 Smart Publisher | 2017-09-29 | 6.8 MEDIUM | N/A |
Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter. | |||||
CVE-2008-0423 | 1 Lama | 1 Lama Software | 2017-09-29 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/. |