Total
2906 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-7123 | 1 Zkup | 1 Zkup | 2017-09-28 | 6.8 MEDIUM | N/A |
Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php via a null byte (%00) in the login parameter in an ajout action, which bypasses the regular expression check. | |||||
CVE-2008-7073 | 2 Ekkaia, Rssmodule | 2 Pie Web, Rss Module | 2017-09-28 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lib parameter. | |||||
CVE-2009-0103 | 1 Playsms | 1 Playsms | 2017-09-28 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php. | |||||
CVE-2008-6513 | 1 Aphpkb | 1 Aphpkb | 2017-09-28 | 6.8 MEDIUM | N/A |
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php. | |||||
CVE-2008-6287 | 1 Getmiro | 1 Broadcast Machine | 2017-09-28 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/. | |||||
CVE-2008-7067 | 1 Pagetreecms | 1 Page Tree Cms | 2017-09-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[PT_Config][dir][data] parameter. | |||||
CVE-2008-7042 | 1 Freshscripts | 1 Fresh Email Script | 2017-09-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter. | |||||
CVE-2008-6178 | 2 Fckeditor, Phplist | 2 Fckeditor, Phplist | 2017-09-28 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-0701 | 1 Cybershade | 1 Cybershadecms | 2017-09-28 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters. | |||||
CVE-2009-0643 | 1 Dminnich | 1 Simple Php News | 2017-09-28 | 5.1 MEDIUM | N/A |
Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-0639 | 1 Phpyabs | 1 Phpyabs | 2017-09-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter. | |||||
CVE-2009-0251 | 1 Ryneezy | 1 Phosheezy | 2017-09-28 | 6.5 MEDIUM | N/A |
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6983 | 1 Devalcms | 1 Devalcms | 2017-09-28 | 7.5 HIGH | N/A |
modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php. | |||||
CVE-2008-6958 | 1 Comsenz | 1 Crossday Discuz\! Board | 2017-09-28 | 6.5 MEDIUM | N/A |
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. | |||||
CVE-2008-6305 | 1 Freedirectoryscript | 1 Free Directory Script | 2017-09-28 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_DIR parameter. | |||||
CVE-2008-6315 | 1 Phpmygallery | 1 Phpmygallery | 2017-09-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to execute arbitrary PHP code via a URL in the confdir parameter, a different issue than CVE-2008-6316. | |||||
CVE-2008-6936 | 1 Jabber | 1 Exodus | 2017-09-28 | 9.3 HIGH | N/A |
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935. | |||||
CVE-2009-0595 | 1 Phpskelsite | 1 Phpskelsite | 2017-09-28 | 5.1 MEDIUM | N/A |
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter. | |||||
CVE-2008-6934 | 1 Sansuart | 1 Free Simple Guestbook Php Script | 2017-09-28 | 7.5 HIGH | N/A |
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-6318 | 1 Phpmygallery | 1 Phpmygallery | 2017-09-28 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter, a different vector than CVE-2008-6317. |