Total
6541 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-6195 | 1 Landesk | 1 Landesk Management Suite | 2024-11-21 | 7.8 HIGH | N/A |
Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643. | |||||
CVE-2008-6183 | 1 Myphpindexer | 1 My Php Indexer | 2024-11-21 | 7.8 HIGH | N/A |
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters. | |||||
CVE-2008-6177 | 1 Publicwarehouse | 1 Lightblog | 2024-11-21 | 6.8 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view_member.php, (2) username_post parameter to login.php, and the (3) Lightblog_username cookie parameter to check_user.php. | |||||
CVE-2008-6172 | 2 Joomla, Weberr | 2 Joomla, Rwcards | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter. | |||||
CVE-2008-6167 | 1 Miniportail | 1 Miniportail | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lng parameter. | |||||
CVE-2008-6139 | 1 Webbiscuits | 1 Modules Controller | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter. | |||||
CVE-2008-6129 | 1 Mozilo | 1 Mozilowiki | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | |||||
CVE-2008-6126 | 1 Mozilo | 1 Mozilocms | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) page parameter to index.php, a different vector than CVE-2008-3589. | |||||
CVE-2008-6112 | 1 Scriptsez | 1 Ez Ringtone Manager | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) main.php and (2) template.php in ringtones/. | |||||
CVE-2008-6090 | 1 Scriptsez | 1 Mini Hosting Panel | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action. | |||||
CVE-2008-6089 | 1 Scriptsez | 1 Easy Image Downloader | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action. | |||||
CVE-2008-6083 | 1 Txtshop | 1 Txtshop | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. | |||||
CVE-2008-6080 | 2 Codecall, Joomla | 2 Com Ionfiles, Joomla | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |||||
CVE-2008-6074 | 1 Phpcrs | 1 Phpcrs | 2024-11-21 | 5.1 MEDIUM | N/A |
Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter. | |||||
CVE-2008-6025 | 1 Openelec | 1 Openelec | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj parameter. | |||||
CVE-2008-6018 | 1 Myphpsite | 1 Myphpsite | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter. | |||||
CVE-2008-6012 | 1 Hardkap | 1 Pritlog | 2024-11-21 | 4.3 MEDIUM | N/A |
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a viewEntry action. | |||||
CVE-2008-6010 | 1 Sg Real Estate Portal | 1 Sg Real Estate Portal | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php. | |||||
CVE-2008-6002 | 1 Web-cp | 1 Web-cp | 2024-11-21 | 7.1 HIGH | N/A |
Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation parameter. | |||||
CVE-2008-5997 | 1 Ocp2 | 1 Omnicom Content Platform | 2024-11-21 | 7.8 HIGH | N/A |
Absolute path traversal vulnerability in admin/fileKontrola/browser.asp in Omnicom Content Platform (OCP) 2.0 allows remote attackers to list arbitrary directories via a full pathname in the root parameter. |