Total
3411 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-5334 | 1 Nitrotech | 1 Nitrotech | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | |||||
CVE-2008-5332 | 1 Pie | 1 Pie | 2017-09-29 | 10.0 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php, (b) cancel.php, (c) context.php, (d) deadlinks.php, (e) delete.php, and others; and the (2) GLOBALS[pie][library_path] parameter to files in lib/share/ including (f) diff.php, (g) file.php, (h) locale.php, (i) mapfile.php, (j) page.php, and others. | |||||
CVE-2008-5288 | 1 Scripts4you | 1 Faq Manager | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config_path parameter. | |||||
CVE-2008-5210 | 1 Phpblock | 1 Phpblock | 2017-09-29 | 9.3 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in script/tick/, and (4) modules/dungeon/tick/allincludefortick.php, different vectors than CVE-2008-1776. | |||||
CVE-2008-5167 | 1 Boonex | 1 Orca | 2017-09-29 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter. | |||||
CVE-2008-5071 | 1 Yoxel | 1 Yoxel | 2017-09-29 | 9.0 HIGH | N/A |
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP code via the proj_id parameter. | |||||
CVE-2008-5066 | 1 Agaresmedia | 1 Themesitescript | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter. | |||||
CVE-2008-5063 | 1 Otmanager | 1 Otmanager | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the Tipo parameter. | |||||
CVE-2008-5060 | 1 Modernbill | 1 Modernbill | 2017-09-29 | 10.0 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php in include/scripts/; (4) include/misc/mod_2checkout/2checkout_return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054. | |||||
CVE-2008-5053 | 1 Joomla | 2 Com Rssreader, Joomla | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | |||||
CVE-2008-5015 | 1 Mozilla | 1 Firefox | 2017-09-29 | 5.1 MEDIUM | N/A |
Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system. | |||||
CVE-2008-4735 | 1 Coastal | 1 Coast | 2017-09-29 | 8.5 HIGH | N/A |
PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter. | |||||
CVE-2008-4720 | 1 Arzdev | 1 Gemini Portal | 2017-09-29 | 9.3 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php. | |||||
CVE-2008-4719 | 1 Openengine | 1 Openengine | 2017-09-29 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter, a different vector than CVE-2008-4329. | |||||
CVE-2008-4704 | 1 Mitre | 1 Sezhoo | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. | |||||
CVE-2008-4673 | 1 Webbiscuits | 1 Events Calendar | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the (1) path[docroot] and (2) component parameters. | |||||
CVE-2008-4645 | 1 Phpwebgallery | 1 Phpwebgallery | 2017-09-29 | 9.0 HIGH | N/A |
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function. | |||||
CVE-2008-4624 | 1 Ftrsoft | 1 Fast Click Sql Lite | 2017-09-29 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] parameter. | |||||
CVE-2008-4557 | 1 Cutephp | 1 Cutenews | 2017-09-29 | 10.0 HIGH | N/A |
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression. | |||||
CVE-2008-4529 | 1 Asicms | 1 Asicms | 2017-09-29 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4) DumbStore.php, (5) Extension.php, (6) FileStore.php, (7) HMAC.php, (8) MemcachedStore.php, (9) Message.php, (10) Nonce.php, (11) SQLStore.php, (12) SReg.php, (13) TrustRoot.php, and (14) URINorm.php in classes/Auth/OpenID/; and (15) XRDS.php, (16) XRI.php and (17) XRIRes.php in classes/Auth/Yadis/. |