CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2010-1115 MEDIUM

Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a ..…

CVSS 5.0 EPSS 1.56% Mar 25, 2010
CVE-2010-1114 HIGH

Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 7.5 EPSS 2.99% Mar 25, 2010
CVE-2010-1113 MEDIUM

Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 EPSS 1.44% Mar 25, 2010
CVE-2008-6655 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche…

CVSS 4.3 EPSS 1.48% Apr 7, 2009
CVE-2008-6545 HIGH

PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code…

CVSS 7.5 EPSS 2.33% Mar 30, 2009
CVE-2008-6543 HIGH

Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3,…

CVSS 7.5 EPSS 2.54% Mar 30, 2009
CVE-2007-4937 MEDIUM

CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 p…

CVSS 5.0 EPSS 2.58% Sep 18, 2007
CVE-2007-1144 MEDIUM

Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in th…

CVSS 5.0 EPSS 3.38% Feb 27, 2007
CVE-2007-0361 HIGH

PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrary PHP code via a URL in the chem parame…

CVSS 7.5 EPSS 2.49% Jan 19, 2007
CVE-2006-4754 MEDIUM

Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album paramet…

CVSS 6.8 EPSS 2.23% Sep 13, 2006
CVE-2006-4753 MEDIUM

Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

CVSS 5.0 EPSS 3.47% Sep 13, 2006
CVE-2006-4746 HIGH

PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL…

CVSS 7.5 EPSS 2.63% Sep 13, 2006
CVE-2006-4678 HIGH

PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) ins…

CVSS 7.5 EPSS 2.47% Sep 11, 2006
CVE-2002-2217 HIGH

Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code…

CVSS 7.5 EPSS 2.06% Sep 11, 2006
CVE-2006-4622 HIGH

PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the p…

CVSS 7.5 EPSS 3.37% Sep 7, 2006
CVE-2006-3171 MEDIUM

CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a newline character in the email parameter t…

CVSS 5.0 EPSS 1.49% Jun 23, 2006
CVE-2006-3170 MEDIUM

CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty collapse[] or readall p…

CVSS 5.0 EPSS 1.76% Jun 23, 2006
CVE-2006-3169 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) msg_…

CVSS 4.3 EPSS 1.68% Jun 23, 2006
CVE-2006-3168 HIGH

SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut parameters in (a) re…

CVSS 7.5 EPSS 1.72% Jun 23, 2006

Showing 1 to 19 CVEs · page 1