Total
3411 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-4502 | 1 Datafeedfile | 1 Dff Framework Api | 2017-09-29 | 10.0 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a URL in the DFF_config[dir_include] parameter to (1) DFF_affiliate_client_API.php, (2) DFF_featured_prdt.func.php, (3) DFF_mer.func.php, (4) DFF_mer_prdt.func.php, (5) DFF_paging.func.php, (6) DFF_rss.func.php, and (7) DFF_sku.func.php in include/. | |||||
CVE-2008-4451 | 1 Eset Software | 1 System Analyzer Tool | 2017-09-29 | 7.2 HIGH | N/A |
The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer. | |||||
CVE-2008-4141 | 1 X10media | 1 .x10 Automatic Mp3 Script | 2017-09-29 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php. | |||||
CVE-2008-4138 | 1 Technote | 1 Technote | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter. | |||||
CVE-2008-4134 | 1 Phprealty | 1 Phprealty | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter. | |||||
CVE-2008-3721 | 1 Deeemm | 1 Dmcms | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter. | |||||
CVE-2008-3595 | 1 Txtsql | 1 Txtsql | 2017-09-29 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter. | |||||
CVE-2008-3592 | 1 21degrees | 1 Symphony | 2017-09-29 | 8.5 HIGH | N/A |
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/. | |||||
CVE-2008-3570 | 1 Africabegone | 1 Africa Be Gone | 2017-09-29 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter. | |||||
CVE-2008-3509 | 1 Lovecms | 1 Lovecms | 2017-09-29 | 7.5 HIGH | N/A |
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors. | |||||
CVE-2008-3481 | 1 Coppermine-gallery | 1 Coppermine Photo Gallery | 2017-09-29 | 7.5 HIGH | N/A |
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | |||||
CVE-2008-3455 | 1 Jnshosts | 1 Php Hosting Directory | 2017-09-29 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter. | |||||
CVE-2008-3434 | 1 Apple | 1 Itunes | 2017-09-29 | 7.5 HIGH | N/A |
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3368 | 1 Atutor | 1 Atutor | 2017-09-29 | 6.5 MEDIUM | N/A |
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter. | |||||
CVE-2008-3332 | 1 Mantis | 1 Mantis | 2017-09-29 | 6.5 MEDIUM | N/A |
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter. | |||||
CVE-2008-3308 | 1 Carlos Desseno | 1 Youtube Blog | 2017-09-29 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_archivo parameter. | |||||
CVE-2008-3207 | 1 Pragyan | 1 Praygan Cms | 2017-09-29 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) sourceFolder or (2) moduleFolder parameter. | |||||
CVE-2008-3167 | 1 Boonex | 1 Dolphin | 2017-09-29 | 9.3 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin. | |||||
CVE-2008-3166 | 1 Boonex | 1 Ray | 2017-09-29 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sIncPath parameter. | |||||
CVE-2008-3093 | 1 Phplizardo | 1 Imperialbb | 2017-09-29 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type. |