Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,671 CVEs tagged with CWE-941,962 Critical, 2,225 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2006-4533

Published Sep 1, 2006

Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4476

Published Aug 31, 2006

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4285

Published Aug 22, 2006

PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path]…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4288

Published Aug 22, 2006

PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to exe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4270

Published Aug 21, 2006

PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4195

Published Aug 17, 2006

PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4204

Published Aug 17, 2006

Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_pre paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4215

Published Aug 17, 2006

PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4159

Published Aug 16, 2006

Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _BASE parameter to script…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4130

Published Aug 14, 2006

PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4074

Published Aug 11, 2006

PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4026

Published Aug 9, 2006

PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter in usr/extensions/get_i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3980

Published Aug 5, 2006

PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3995

Published Aug 5, 2006

Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.cl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3947

Published Aug 1, 2006

PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlier component for Mambo allows remote attackers to execute ar…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3949

Published Aug 1, 2006

PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3846

Published Jul 25, 2006

PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosCo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3847

Published Jul 25, 2006

PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mos…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3773

Published Jul 24, 2006

PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PH…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3774

Published Jul 24, 2006

PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3776

Published Jul 24, 2006

PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3777

Published Jul 24, 2006

PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,501-6,525 of 6,671 CVEsPage 261 of 267