2550 vulnerabilidades · Web · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2008-2650
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2008 1 PoC

Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.

CVE-2008-6668
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.6%
2008 1 PoC

Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.

CVE-2008-4764
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.5%
2008 1 PoC

Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.

CVE-2008-6982
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.6%
2008 2 PoCs

Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.

CVE-2008-6222
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.7%
2008 1 PoC

Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php.

CVE-2008-6172
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2008 1 PoC

Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.

CVE-2008-1061
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2008 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url parameter to (e) view/admin/submenu.php; and the (3) page parameter to (f) view/admin/pager.php.

CVE-2008-7269
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.5%
2008 1 PoC

Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.

CVE-2023-3460
Ultimate Member Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2023 14 PoCs

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVE-2008-5587
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2008 2 PoCs

Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.

CVE-2008-6080
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.1%
2008 1 PoC

Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2008-6465
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2008 0 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.

CVE-2008-4668
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.0%
2008 2 PoCs

Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.

CVE-2008-2398
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.8%
2008 0 PoCs

Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.

CVE-2008-1059
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2008 2 PoCs

PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.

CVE-2015-7297
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2015 5 PoCs

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

CVE-2017-18580
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.0%
2017 0 PoCs

The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.

CVE-2017-14535
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.6%
2017 3 PoCs

trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

CVE-2017-3528
Applications Framework Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
43.2%
2017 2 PoCs

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks