Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,671 CVEs tagged with CWE-941,962 Critical, 2,225 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2006-0207

Published Jan 13, 2006

Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session e…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0144

Published Jan 9, 2006

The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0094

Published Jan 5, 2006

PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerabil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0064

Published Jan 3, 2006

PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4874

Published Dec 31, 2005

The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-For…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4573

Published Dec 29, 2005

PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4209

Published Dec 13, 2005

WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail messa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3859

Published Nov 29, 2005

PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3861

Published Nov 29, 2005

PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3835

Published Nov 26, 2005

PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the main parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3775

Published Nov 23, 2005

PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3554

Published Nov 16, 2005

Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3302

Published Oct 24, 2005

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eva…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2703

Published Sep 23, 2005

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2837

Published Sep 7, 2005

Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2498

Published Aug 15, 2005

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgrou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1965

Published Jun 16, 2005

PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1996

Published Jun 15, 2005

PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1876

Published Jun 9, 2005

Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1894

Published Jun 9, 2005

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,601-6,625 of 6,671 CVEsPage 265 of 267