Total
5025 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-0458 | 1 Slaed | 1 Slaed Cms | 2017-09-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php. | |||||
CVE-2008-0464 | 1 Absofort | 1 Aconon Mail Enterprise Sql | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter. | |||||
CVE-2008-0465 | 1 Seagullproject.org | 1 Seagull | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter. | |||||
CVE-2008-1635 | 1 Raven Php Scripts | 1 Keep It Simple Guest Book | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected. | |||||
CVE-2008-0501 | 1 Sourceforge | 1 Phpmyclub | 2017-09-28 | 5.8 MEDIUM | N/A |
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI. | |||||
CVE-2008-0521 | 1 Bubbling Library | 1 Bubbling Library | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545. | |||||
CVE-2008-0542 | 1 Gerd Tentler | 1 Simple Forum | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2008-0545 | 1 Bubbling Library | 1 Bubbling Library | 2017-09-28 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521. | |||||
CVE-2008-0602 | 1 All Club Cms | 1 All Club Cms | 2017-09-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter. | |||||
CVE-2008-1645 | 1 Guillaume Meister | 1 Php Spammanager | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot dot) in the filename parameter. | |||||
CVE-2008-0745 | 1 Domphp | 1 Domphp | 2017-09-28 | 7.5 HIGH | N/A |
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |||||
CVE-2008-0794 | 1 Affiliate Market | 1 Affiliate Market | 2017-09-28 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. | |||||
CVE-2008-0813 | 1 Xpweb | 1 Xpweb | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. | |||||
CVE-2008-0814 | 1 Truc | 1 Truc | 2017-09-28 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the upload_filename parameter. | |||||
CVE-2008-0818 | 1 Freephpgallery | 1 Freephpgallery | 2017-09-28 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie to (1) comment.php, (2) index.php, and (3) show.php. | |||||
CVE-2008-0905 | 1 Meo | 1 Globsy | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2008-1042 | 1 Linux Web Shop | 1 Php Download Manager | 2017-09-28 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. | |||||
CVE-2008-1125 | 1 Podcast Generator | 1 Podcast Generator | 2017-09-28 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) theme_path parameter to core/themes.php and the (2) filename parameter to download.php. | |||||
CVE-2008-1119 | 1 Centreon | 1 Centreon | 2017-09-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter. | |||||
CVE-2008-1231 | 1 Jspwiki | 1 Jspwiki | 2017-09-28 | 9.3 HIGH | N/A |
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter. |