Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,671 CVEs tagged with CWE-941,962 Critical, 2,225 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2006-5191

Published Oct 10, 2006

PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute ar…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5220

Published Oct 10, 2006

Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludeP…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5101

Published Oct 3, 2006

PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) C…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5093

Published Sep 29, 2006

PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5055

Published Sep 28, 2006

PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5021

Published Sep 27, 2006

Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5043

Published Sep 27, 2006

Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5045

Published Sep 27, 2006

Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4694

Published Sep 27, 2006

Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2006-4965

Published Sep 25, 2006

Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4944

Published Sep 23, 2006

PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4869

Published Sep 19, 2006

PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4858

Published Sep 19, 2006

PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbit…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4863

Published Sep 19, 2006

Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3442

Published Sep 12, 2006

Unspecified vulnerability in Pragmatic General Multicast (PGM) in Microsoft Windows XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted multicast me…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4671

Published Sep 11, 2006

PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONF…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4672

Published Sep 11, 2006

PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrary PHP code via a URL in the (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4666

Published Sep 9, 2006

Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4649

Published Sep 8, 2006

PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4637

Published Sep 8, 2006

Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4639

Published Sep 8, 2006

Multiple PHP remote file inclusion vulnerabilities in C-News.fr C-News 1.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code vi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4624

Published Sep 7, 2006

CRLF injection vulnerability in Utils.py in Mailman before 2.1.9rc1 allows remote attackers to spoof messages in the error log and possibly trick the administrator into visiting m…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4583

Published Sep 6, 2006

Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/cm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,476-6,500 of 6,671 CVEsPage 260 of 267