Vulnerabilities (CVE)

Filtered by CWE-20
Total 13238 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6751 1 Revou 2 Revou, Tclone 2026-06-16 6.8 MEDIUM N/A
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo.
CVE-2008-6750 1 China-on-site 1 Flexphpdirectory 2026-06-16 6.8 MEDIUM N/A
Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.
CVE-2008-6745 1 Blogphp 1 Blogphp 2026-06-16 7.5 HIGH N/A
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action.
CVE-2008-6742 1 Gofoxy 1 Foxy 2026-06-16 4.3 MEDIUM N/A
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value.
CVE-2008-6731 1 China-on-site 1 Flexphplink 2026-06-16 9.3 HIGH N/A
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the renamed file in linkphoto/.
CVE-2008-6702 1 Stalker-game 1 S.t.a.l.k.e.r.\ 2026-06-16 5.0 MEDIUM N/A
S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.
CVE-2008-6684 1 Yourfreeworld 1 Apartment Search Script 2026-06-16 6.8 MEDIUM N/A
Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct request to a renamed file in Member_Admin/logo/.
CVE-2008-6676 1 Quickersite 1 Quickersite 2026-06-16 5.0 MEDIUM N/A
QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message.
CVE-2008-6662 2 Avg, Linux 2 Avg Anti-virus, Linux Kernel 2026-06-16 4.3 MEDIUM N/A
AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption.
CVE-2008-6568 1 Yehe 1 Yehe 2026-06-16 6.8 MEDIUM N/A
Unrestricted file upload vulnerability in Yehe 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the envoyer feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6559 1 Sco 2 Reliantha, Unixware 2026-06-16 7.2 HIGH N/A
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. (dot dot) sequences that point to a directory containing a file whose name includes shell metacharacters.
CVE-2008-6558 2 Sco, Unixware 2 Unixware, Reliantha 2026-06-16 7.2 HIGH N/A
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program.
CVE-2008-6557 1 Puppetmaster 1 Webutil 2026-06-16 10.0 HIGH N/A
cgi-bin/webutil.pl in The Puppet Master WebUtil 2.7 allows remote attackers to execute arbitrary commands via shell metacharacters in the details command.
CVE-2008-6556 1 Puppet Master 1 Webutil 2026-06-16 10.0 HIGH N/A
cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the whois command.
CVE-2008-6555 1 Puppetmaster 1 Webutil 2026-06-16 10.0 HIGH N/A
cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command.
CVE-2008-6547 1 Formencode 1 Formencode 2026-06-16 7.5 HIGH N/A
schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.
CVE-2008-6541 1 Dnnsoftware 1 Dotnetnuke 2026-06-16 6.8 MEDIUM N/A
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
CVE-2008-6538 1 Holger Schurig 1 Destar 2026-06-16 5.0 MEDIUM N/A
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
CVE-2008-6534 1 Vwsolutions 1 Null Ftp 2026-06-16 7.1 HIGH N/A
Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custom SITE command containing shell metacharacters such as "&" (ampersand) in the middle of an argument.
CVE-2008-6528 1 Tmaxsoft 1 Jeus 2026-06-16 5.0 MEDIUM N/A
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.