Total
6542 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-2223 | 1 Teozkr | 1 Lightopencms | 2024-11-21 | 9.3 HIGH | N/A |
Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote file inclusion attacks may be possible. | |||||
CVE-2009-2222 | 1 Php.s3 | 1 Php-i-board | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors, probably related to mail. | |||||
CVE-2009-2220 | 1 Tribiq | 1 Tribiq Cms | 2024-11-21 | 5.1 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary files via directory traversal sequences in the template_path parameter to (1) masthead.inc.php, (2) toppanel.inc.php, and (3) contact.inc.php in templates/mytribiqsite/tribiq-CL-9000/includes; and the use_template_family parameter to (4) templates/mytribiqsite/tribiq-CL-9000/includes/nlarlist_content.inc.php. NOTE: the tribal-GPL-1066/includes/header.inc.php vector is already covered by CVE-2008-4894. | |||||
CVE-2009-2184 | 1 Gravy-media | 1 Media Photo Host | 2024-11-21 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to read arbitrary files via an encoded "/" (slash) in the file parameter. | |||||
CVE-2009-2183 | 1 Campware.org | 1 Campsite | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the GLOBALS[g_campsiteDir] parameter. | |||||
CVE-2009-2180 | 1 Pc4arb | 1 Pc4 Uploader | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter. | |||||
CVE-2009-2177 | 1 Fuzzylime | 1 Fuzzylime Cms | 2024-11-21 | 6.8 MEDIUM | N/A |
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a "../" value. | |||||
CVE-2009-2176 | 1 Fuzzylime | 1 Fuzzylime Cms | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) list parameter to code/confirm.php and the (2) template parameter to code/display.php. | |||||
CVE-2009-2166 | 2 Ocsinventory-ng, Unix | 2 Ocs Inventory Ng, Unix | 2024-11-21 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter. | |||||
CVE-2009-2161 | 1 Torrenttrader | 1 Torrenttrader Classic | 2024-11-21 | 5.1 MEDIUM | N/A |
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name. | |||||
CVE-2009-2151 | 1 Adaptweb | 1 Adaptweb | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the newlang parameter. | |||||
CVE-2009-2132 | 1 4homepages | 1 4images | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter. | |||||
CVE-2009-2124 | 1 Elvinbts | 1 Elvinbts | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter. | |||||
CVE-2009-2116 | 1 Skybluecanvas | 1 Skybluecanvas | 2024-11-21 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter. | |||||
CVE-2009-2112 | 1 Frank-karau | 1 Phpfk | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _FORUM[settings_design_style] parameter. | |||||
CVE-2009-2110 | 1 Jnmsolutions | 1 Db Top Sites | 2024-11-21 | 7.6 HIGH | N/A |
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the u parameter to (1) full.php, (2) index.php, and (3) contact.php. | |||||
CVE-2009-2109 | 1 Fretsweb Project | 1 Fretsweb | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php. | |||||
CVE-2009-2101 | 1 Castro Xl | 1 Torrentvolve | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter. | |||||
CVE-2009-2100 | 2 Joomla, Joomlapraise | 2 Joomla, Com Projectfork | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php. | |||||
CVE-2009-2081 | 1 Phpwebthings | 1 Phpwebthings | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter. |