Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
file inclusion vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-4541
Multiple PHP remote file inclusion vulnerabilities in IsolSoft Support Center 2.5 allow remote malicious users to execute arbitrary PHP code via a URL in the lang parameter to (1) newticket.php or (2) rempass.php, or a URL in the lang parameter in an adduser action to (3) index.p...
Isolsoft Support Center 2.5
1 EDB exploit
NA
CVE-2009-4542
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote malicious users to inject arbitrary web script or HTML via the lang parameter.
Isolsoft Support Center 2.5
1 EDB exploit
NA
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module prior to 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilder_step2.php...
Bitrix Mpbuilder
1 EDB exploit
NA
CVE-2011-1099
Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls prior to 1.0.2 allow remote malicious users to (1) read arbitrary files via a .. (dot dot) in the p parameter in a preview action to index.php, or (2) delete arbitrary files via a .. (dot dot) in the p par...
Focalmedia.net Quick Polls
1 EDB exploit
NA
CVE-2006-5291
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote malicious users to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third part...
Alex Downloadengine 1.4.2
2 EDB exploits
NA
CVE-2011-4614
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x prior to 4.5.9, 4.6.x prior to 4.6.2, and development versions of 4.7 allows remote malicious users to execute arbitrary PHP code via a URL in th...
Typo3 Typo3 4.5.3
Typo3 Typo3 4.5.5
Typo3 Typo3 4.5.8
Typo3 Typo3 4.5.7
Typo3 Typo3 4.5.6
Typo3 Typo3 4.5
Typo3 Typo3 4.5.1
Typo3 Typo3 4.5.4
Typo3 Typo3 4.5.2
Typo3 Typo3 4.6
Typo3 Typo3 4.6.1
1 EDB exploit
NA
CVE-2014-5465
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and previous versions for WordPress allows remote malicious users to read arbitrary files via a .. (dot dot) in the file parameter.
Werdswords Download Shortcode 0.2
Werdswords Download Shortcode 0.1
Werdswords Download Shortcode 0.2.2
Werdswords Download Shortcode
1 EDB exploit
NA
CVE-2007-4551
PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote malicious users to execute arbitrary PHP code via a URL in the loadpage parameter.
Agares Media Arcadem 2.0.1
2 EDB exploits
NA
CVE-2008-2980
Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote malicious users to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin...
Homeph Design Homeph Design 2.10
1 EDB exploit
NA
CVE-2008-2981
PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the thumb_template parameter.
Homeph Design Homeph Design 2.10
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
7
8
9
10
NEXT »