Total
3761 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-1215 | 1 Mozilla | 2 Firefox, Thunderbird | 2017-09-19 | 6.8 MEDIUM | N/A |
Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope." | |||||
CVE-2009-4834 | 1 Xpressengine | 1 Zeroboard | 2017-09-19 | 6.8 MEDIUM | N/A |
lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php. | |||||
CVE-2009-4887 | 1 Sbuilder | 1 Cms S.builder | 2017-09-19 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in index.php in CMS S.Builder 3.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in a binn_include_path cookie. NOTE: this can also be leveraged to include and execute arbitrary local files. | |||||
CVE-2010-0046 | 1 Apple | 1 Safari | 2017-09-19 | 9.3 HIGH | N/A |
The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments. | |||||
CVE-2009-5095 | 1 Ea-style | 1 Gbook | 2017-09-19 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_ordner parameter. | |||||
CVE-2009-4793 | 1 Karl Core | 1 Bandsite Cms | 2017-09-19 | 6.0 MEDIUM | N/A |
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-4739 | 1 Skadate | 1 Skadate Online Dating Software | 2017-09-19 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences. | |||||
CVE-2009-4993 | 1 Script-shop24 | 1 Lm Starmail Paidmail | 2017-09-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |||||
CVE-2009-4836 | 1 Moviephp | 1 Movie Php Script | 2017-09-19 | 7.5 HIGH | N/A |
Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter. | |||||
CVE-2010-1121 | 1 Mozilla | 1 Firefox | 2017-09-19 | 10.0 HIGH | N/A |
Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010. | |||||
CVE-2009-4666 | 1 Qualityunit | 1 Download Protect | 2017-09-19 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[RootPath] parameter to (1) Framework/EmailTemplates.class.php, (2) Customers/PDPEmailReplaceConstants.class.php, and (3) Admin/ResellersManager.class.php in includes/DProtect/. | |||||
CVE-2009-3541 | 1 Phpgenealogy | 1 Phpgenealogy | 2017-09-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter. | |||||
CVE-2009-2634 | 2 Joomla, Ordasoft | 2 Joomla, Com Medialibrary | 2017-09-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |||||
CVE-2009-2641 | 1 Rich White | 1 School Data Nav | 2017-09-19 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences. | |||||
CVE-2009-3065 | 1 Rein Velt | 1 Vedit | 2017-09-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the highlighter parameter. | |||||
CVE-2009-3079 | 1 Mozilla | 1 Firefox | 2017-09-19 | 10.0 HIGH | N/A |
Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter. | |||||
CVE-2009-3365 | 1 Traza | 1 Aurora | 2017-09-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the AURORA_MODULES_FOLDER parameter. | |||||
CVE-2009-3760 | 1 Citrix | 1 Xencenterweb | 2017-09-19 | 7.5 HIGH | N/A |
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-3464 | 1 Adobe | 1 Shockwave Player | 2017-09-19 | 9.3 HIGH | N/A |
Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-3333 | 2 Alibasta, Mambo | 2 Com Koesubmit, Mambo | 2017-09-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. |