Total
3701 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-3638 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2024-11-21 | 9.3 HIGH | N/A |
Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs. | |||||
CVE-2008-3595 | 1 Txtsql | 1 Txtsql | 2024-11-21 | 9.3 HIGH | N/A |
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter. | |||||
CVE-2008-3592 | 1 21degrees | 1 Symphony | 2024-11-21 | 8.5 HIGH | N/A |
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/. | |||||
CVE-2008-3575 | 1 Ezcontents | 1 Ezcontents Cms | 2024-11-21 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[gsLanguage] parameter, a different vector than CVE-2006-4477 and CVE-2004-0132. | |||||
CVE-2008-3570 | 1 Africabegone | 1 Africa Be Gone | 2024-11-21 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter. | |||||
CVE-2008-3509 | 1 Lovecms | 1 Lovecms | 2024-11-21 | 7.5 HIGH | N/A |
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors. | |||||
CVE-2008-3481 | 1 Coppermine-gallery | 1 Coppermine Photo Gallery | 2024-11-21 | 7.5 HIGH | N/A |
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | |||||
CVE-2008-3455 | 1 Jnshosts | 1 Php Hosting Directory | 2024-11-21 | 10.0 HIGH | N/A |
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter. | |||||
CVE-2008-3442 | 1 Winzip | 1 Winzip | 2024-11-21 | 7.5 HIGH | N/A |
WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3441 | 1 Nullsoft | 1 Winamp | 2024-11-21 | 7.5 HIGH | N/A |
Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3440 | 1 Sun | 1 Java | 2024-11-21 | 7.5 HIGH | N/A |
Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3439 | 1 Speedbit | 1 Speedbit Video Accelerator | 2024-11-21 | 7.5 HIGH | N/A |
SpeedBit Video Acceleration before 2.2.1.8 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3437 | 1 Openoffice | 1 Openoffice.org | 2024-11-21 | 7.5 HIGH | N/A |
OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3436 | 1 Notepad\+\+ | 1 Notepad\+\+ | 2024-11-21 | 7.5 HIGH | N/A |
The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3435 | 1 Linkedin | 1 Browser Toolbar | 2024-11-21 | 7.5 HIGH | N/A |
LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3434 | 1 Apple | 1 Itunes | 2024-11-21 | 7.5 HIGH | N/A |
Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3433 | 1 Speedbit | 1 Download Accelerator Plus | 2024-11-21 | 7.5 HIGH | N/A |
SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |||||
CVE-2008-3402 | 1 Hscripts | 1 Hiox Random Ad | 2024-11-21 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php. | |||||
CVE-2008-3401 | 1 Hscripts | 1 Hiox Random Ad | 2024-11-21 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter. | |||||
CVE-2008-3399 | 1 Xrms | 1 Xrms Crm | 2024-11-21 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter. |