Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via
Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary fi
export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id pa
relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta is not removed after installation and does not
CRLF injection vulnerability in layers_toggle.php in WebCalendar 1.0.1 might allow remote attackers to modify HTTP heade
PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote
PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attac
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value,
The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access c
Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary fi
search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive inf
WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, w
Nodezilla 0.4.13-corno-fulgure does not properly protect the evl_data directory, which could allow them to be shared whe
e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.
e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which i
Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows rem
The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMy
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote atta
xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path
Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows
Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (Suga
Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of ser
Lyris ListManager before 8.9b allows remote attackers to obtain sensitive information via a request to the TCLHTTPd stat
Lyris ListManager 8.5, and possibly other versions before 8.8, includes sensitive information in the env hidden variable
Lyris ListManager 8.8 through 8.9b allows remote attackers to obtain sensitive information by causing errors in TML scri
Directory traversal vulnerability in getdox.php in Torrential 1.2 allows remote attackers to read arbitrary files via ".
Directory traversal vulnerability in captcha.php in Captcha PHP 0.9 allows remote attackers to read arbitrary files via
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information via a direct request to storyblock.ph
eFiction 1.0, 1.1, and 2.0 allows remote attackers to obtain sensitive information by accessing phpinfo.php, which execu
Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cau
Directory traversal vulnerability in My Album Online 1.0 allows remote attackers to access arbitrary files via ".../" (t
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot)
Opera before 8.51, when running on Windows with Input Method Editor (IME) installed, allows remote attackers to cause a
Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends
Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary loc
phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks th
setting.php in Innovative CMS (ICMS, formerly Imoel-CMS) contains username and password information in cleartext, which
Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via t
Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Managemen
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficien
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service
Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitr
index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id
Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbi
Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct re
The web interface for American Power Conversion (APC) PowerChute Network Shutdown performs all communication in cleartex
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allow
Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary f
Scan for 2005 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started