VYPR

CVEs

383,898 total · page 7054 of 7,678

  • CVE-2008-2942Jun 30, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.

  • CVE-2008-2901Jun 30, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address parameter to addressbook.php, the (2) getnews parameter to familynews.php, and the (3) poll_id…

  • CVE-2008-2902Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.

  • CVE-2008-2903Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.

  • CVE-2008-2904Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • CVE-2008-2905Jun 30, 2008
    risk 0.04cvss —epss 0.18

    PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2008-2906Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.

  • CVE-2008-2907Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.

  • CVE-2008-2908Jun 30, 2008
    risk 0.06cvss —epss 0.35

    Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of…

  • CVE-2008-2909Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter.

  • CVE-2008-2910Jun 30, 2008
    risk 0.04cvss —epss 0.09

    Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting property value.

  • CVE-2008-2911Jun 30, 2008
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.

  • CVE-2008-2912Jun 30, 2008
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_search.php; the (2) cfg[path][contenido] parameter to (b) move_articles.php, (c)…

  • CVE-2008-2913Jun 30, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and .....…

  • CVE-2008-2914Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-2915Jun 30, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execute arbitrary SQL commands via the (1) position or (2) kw parameter.

  • CVE-2008-2916Jun 30, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to showcategory.php and the (2) id parameter to software-description.php.

  • CVE-2008-2917Jun 30, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

  • CVE-2008-2918Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.

  • CVE-2008-2919Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the sort parameter.

  • CVE-2008-2920Jun 30, 2008
    risk 0.03cvss —epss 0.03

    admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.

  • CVE-2008-2921Jun 30, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2008-2922Jun 30, 2008
    risk 0.03cvss —epss 0.05

    Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long IRC message.

  • CVE-2008-2923Jun 30, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to inject arbitrary web script or HTML via the words parameter.

  • CVE-2008-2924Jun 30, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Webmatic before 2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-2925Jun 30, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2008-2884Jun 27, 2008
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2008-2885Jun 27, 2008
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CLASSES_ROOT…

  • CVE-2008-2886Jun 27, 2008
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.

  • CVE-2008-2887Jun 27, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

  • CVE-2008-2888Jun 27, 2008
    risk 0.04cvss —epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[application][app_root] parameter to (1) collection.class.php and (2) content_image.class.php in…

  • CVE-2008-2889Jun 27, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.

  • CVE-2008-2890Jun 27, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter…

  • CVE-2008-2891Jun 27, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a category action.

  • CVE-2008-2892Jun 27, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.

  • CVE-2008-2893Jun 27, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.

  • CVE-2008-2894Jun 27, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

  • CVE-2008-2895Jun 27, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

  • CVE-2008-2896Jun 27, 2008
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

  • CVE-2008-2897Jun 27, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

  • CVE-2008-2898Jun 27, 2008
    risk 0.04cvss —epss 0.07

    Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by…

  • CVE-2008-2899Jun 27, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in includes/classes/page.php in j00lean-CMS 1.03 has unknown impact and attack vectors.

  • CVE-2008-2900Jun 27, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2008-2061Jun 26, 2008
    risk 0.00cvss —epss 0.02

    The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.

  • CVE-2008-2062Jun 26, 2008
    risk 0.00cvss —epss 0.02

    The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct…

  • CVE-2008-2730Jun 26, 2008
    risk 0.00cvss —epss 0.02

    The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP…

  • CVE-2008-2867Jun 26, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.

  • CVE-2008-2868Jun 26, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.

  • CVE-2008-2869Jun 26, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

  • CVE-2008-2870Jun 26, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via the (1) eventID parameter to event_info.php and the (2) userID parameter to list_user.php.