Total
2906 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-7911 | 1 Cybervision | 1 Kaa Iot Platform | 2017-11-02 | 6.5 MEDIUM | 8.8 HIGH |
A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified, which may allow remote code execution. | |||||
CVE-2017-6455 | 1 Ntp | 1 Ntp | 2017-10-23 | 4.4 MEDIUM | 7.0 HIGH |
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable. | |||||
CVE-2008-6223 | 1 Wotw | 1 Way Of The Warrior | 2017-10-18 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the plancia parameter to crea.php. | |||||
CVE-2007-0983 | 1 Ansatheus | 1 At Contenator | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter. | |||||
CVE-2007-0501 | 1 Mafia Scum Tools | 1 Mafia Scum Tools | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter. | |||||
CVE-2007-0499 | 1 Sangwan Kim | 1 Phpindexpage | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter. | |||||
CVE-2007-5099 | 1 David Watters | 1 Helplink | 2017-10-18 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | |||||
CVE-2007-5102 | 1 Wordsmith | 1 Wordsmith | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _path parameter. | |||||
CVE-2007-5117 | 1 Frontaccounting | 1 Frontaccounting | 2017-10-18 | 9.3 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.13, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/login.php and (2) includes/lang/language.php, different vectors than CVE-2007-4279. | |||||
CVE-2007-5321 | 1 Verlihub-project | 1 Verlihub Control Panel | 2017-10-18 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. | |||||
CVE-2007-6147 | 1 Iaprcommence | 1 Iapr Commence | 2017-10-18 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_path parameter to various PHP scripts under (1) admin/includes/, (2) admin/phase/, (3) includes/, (4) includes/page_includes/, (5) reviewer/includes/, (6) reviewer/phase/, and (7) user/phase/. | |||||
CVE-2007-6347 | 1 Viart | 4 Cms, Helpdesk, Shop Evaluation and 1 more | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-6614 | 1 Agares Media | 1 Phpautovideo | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter, a related issue to CVE-2007-6542. | |||||
CVE-2007-6615 | 1 Agares Media | 1 Phpautovideo | 2017-10-18 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the selected_provider parameter. | |||||
CVE-2006-2685 | 1 Kevin Johnson | 1 Basic Analysis And Security Engine | 2017-10-18 | 4.0 MEDIUM | N/A |
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (2) base_stat_common.php, and (3) includes/base_include.inc.php. | |||||
CVE-2006-6976 | 1 Centipaid | 1 Centipaid | 2017-10-18 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to execute arbitrary code via a URL in the absolute_path parameter. | |||||
CVE-2006-6962 | 1 Joomla | 1 Rs Gallery2 | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter. NOTE: this issue may overlap CVE-2006-5047. | |||||
CVE-2006-6760 | 1 Phpmymanga | 1 Phpmymanga | 2017-10-18 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) actionsPage or (2) formPage parameter. | |||||
CVE-2006-6739 | 1 Paristemi | 1 Paristemi | 2017-10-18 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the HTTP_DOCUMENT_ROOT parameter, a different vector than CVE-2006-6689. | |||||
CVE-2006-6738 | 1 Cwm-design | 1 Cwmcounter | 2017-10-18 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in statistic.php in cwmCounter 5.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. |