Total
6537 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-0819 | 1 Plutostatus | 1 Plutostatus Locator | 2024-11-21 | 3.6 LOW | N/A |
Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |||||
CVE-2008-0818 | 1 Freephpgallery | 1 Freephpgallery | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie to (1) comment.php, (2) index.php, and (3) show.php. | |||||
CVE-2008-0814 | 1 Truc | 1 Truc | 2024-11-21 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the upload_filename parameter. | |||||
CVE-2008-0813 | 1 Xpweb | 1 Xpweb | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. | |||||
CVE-2008-0812 | 1 Banpro | 1 Net Banpro Dms | 2024-11-21 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the action parameter. | |||||
CVE-2008-0798 | 1 Artmedic Webdesign | 1 Artmedic Weblog | 2024-11-21 | 4.3 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ta parameter to artmedic_index.php, reached through index.php; and the (2) date parameter to artmedic_print.php. | |||||
CVE-2008-0797 | 1 Itheora | 1 Itheora | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in lib/download.php in iTheora 1.0 rc1 allows remote attackers to read arbitrary files via directory traversal sequences in the url parameter. | |||||
CVE-2008-0794 | 1 Affiliate Market | 1 Affiliate Market | 2024-11-21 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. | |||||
CVE-2008-0790 | 1 Intermate | 1 Winipds | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |||||
CVE-2008-0782 | 1 Moinmoin | 1 Moinmoin | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can be leveraged for PHP code execution via the quicklinks parameter. | |||||
CVE-2008-0760 | 1 Safenet | 2 Sentinel Keys Server, Sentinel Protection Server | 2024-11-21 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483. | |||||
CVE-2008-0758 | 1 Group Logic | 2 Extremez-ip File Server, Extremez-ip Print Server | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a "..\" (dot dot backslash) sequence in the filename. | |||||
CVE-2008-0745 | 1 Domphp | 1 Domphp | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |||||
CVE-2008-0742 | 1 Powerscripts | 1 Powernews | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/; and (2) the page parameter to (g) pnadmin/index.php. NOTE: vector 2 is only exploitable by administrators. | |||||
CVE-2008-0703 | 1 Sflog | 1 Sflog | 2024-11-21 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php. | |||||
CVE-2008-0654 | 1 Azucar Cms | 1 Azucar Cms | 2024-11-21 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in Azucar CMS 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _VIEW (view) parameter to (1) index.php, (2) html/sitio/index.php, or (3) src/sistema/vistas/template/tpl_inicio.php. | |||||
CVE-2008-0615 | 1 Dmsguestbook Project | 1 Dmsguestbook | 2024-11-21 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters. | |||||
CVE-2008-0612 | 1 Xoops | 1 Xoops | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | |||||
CVE-2008-0609 | 1 Divideconcept | 1 Vhd Web Pack | 2024-11-21 | 7.5 HIGH | N/A |
Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |||||
CVE-2008-0602 | 1 All Club Cms | 1 All Club Cms | 2024-11-21 | 6.8 MEDIUM | N/A |
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter. |