CWE-20— Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.— MITRE CWE catalog
13,767 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-20page 17 of 276
- CVE-2008-5674HIGHCVSS v2 9.4EG 9.42008-12-19
Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an inval…
- CVE-2008-5677HIGHCVSS v2 7.1EG 7.12008-12-19
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executab…
- CVE-2008-5678MEDIUMCVSS v2 4.0EG 4.02008-12-19
Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) …
- CVE-2008-5693MEDIUMCVSS v2 5.0EG 5.02008-12-19
Ipswitch WS_FTP Server Manager 6.1.0.0 and earlier, and possibly other Ipswitch products, might allow remote attackers to read the contents of custom ASP files in WSFTPSVR/ via a request with an appended dot character.
- CVE-2008-5695HIGHCVSS v2 8.5EG 8.52008-12-19
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execu…
- CVE-2008-5705HIGHCVSS v2 9.3EG 9.32008-12-22
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an…
- CVE-2008-5709HIGHCVSS v2 9.0EG 9.02008-12-24
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow remote authenticated users to execute arbitrary code via unkn…
- CVE-2008-5712MEDIUMCVSS v2 5.0EG 5.02008-12-24
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or …
- CVE-2008-5715MEDIUMCVSS v2 5.0EG 5.02008-12-24
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported that earlie…
- CVE-2008-5730HIGHCVSS v2 7.5EG 7.52008-12-26
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vectors involving (1) a %0a sequence in a cookie and (2) the add.php file.
- CVE-2008-5732HIGHCVSS v2 7.5EG 7.52008-12-26
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.
- CVE-2008-5810HIGHCVSS v2 10.0EG 10.02009-01-02
WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used du…
- CVE-2008-5826HIGHCVSS v2 7.8EG 7.82009-01-02
The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows remote attackers to cause a denial of service (device crash) via (1) a large value in the payload length field in an NDEF record, or a certain length for a (2) …
- CVE-2008-5870MEDIUMCVSS v2 4.3EG 4.32009-01-08
FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with large width and height values, possibly a related issue to CVE-2007-1942.
- CVE-2008-5872HIGHCVSS v2 7.8EG 7.82009-01-08
Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.13 allow remote attackers to cause a denial of service (devic…
- CVE-2008-5887MEDIUMCVSS v2 5.0EG 5.02009-01-12
phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."
- CVE-2008-5904HIGHCVSS v2 7.5EG 7.52009-01-15
The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflo…
- CVE-2008-5906MEDIUMCVSS v2 6.8EG 6.82009-01-15
Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.
- CVE-2008-5937HIGHCVSS v2 7.8EG 7.82009-01-22
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values.
- CVE-2008-5963HIGHCVSS v2 10.0EG 10.02009-01-23
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter.
- CVE-2008-5966HIGHCVSS v2 7.5EG 7.52009-01-26
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.
- CVE-2008-6058MEDIUMCVSS v2 5.0EG 5.02009-02-05
Syslserve 1.058 and earlier, and probably 1.059, allows remote attackers to cause a denial of service (hang) via a crafted UDP Syslog packet.
- CVE-2008-6084MEDIUMCVSS v2 6.8EG 6.82009-02-06
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request…
- CVE-2008-6119HIGHCVSS v2 7.5EG 7.52009-02-11
Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters. NOTE: t…
- CVE-2008-6121HIGHCVSS v2 7.5EG 7.52009-02-11
CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the PHPSESSID cookie.
- CVE-2008-6122HIGHCVSS v2 7.8EG 7.82009-02-11
The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question mark ("?").
- CVE-2008-6123MEDIUMCVSS v2 5.0EG 5.02009-02-12
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended acc…
- CVE-2008-6175MEDIUMCVSS v2 5.0EG 5.02009-02-19
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command.
- CVE-2008-6185MEDIUMCVSS v2 5.0EG 5.02009-02-19
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command.
- CVE-2008-6207HIGHCVSS v2 8.5EG 8.52009-02-20
Unrestricted file upload vulnerability in form_upload.php in PHPG Upload 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. …
- CVE-2008-6298MEDIUMCVSS v2 5.0EG 5.02009-02-26
Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass intended access restrictions for character encoding and the cookie secure flag via unknown vectors related to the "HTTP header rewrite function."
- CVE-2008-6367HIGHCVSS v2 8.5EG 8.52009-03-02
Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the…
- CVE-2008-6490HIGHCVSS v2 7.5EG 7.52009-03-19
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP fil…
- CVE-2008-6492MEDIUMCVSS v2 6.8EG 6.82009-03-20
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a dir…
- CVE-2008-6497HIGHCVSS v2 7.8EG 7.82009-03-20
The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI.
- CVE-2008-6511MEDIUMCVSS v2 5.8EG 5.82009-03-23
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.
- CVE-2008-6528MEDIUMCVSS v2 5.0EG 5.02009-03-26
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.
- CVE-2008-6534HIGHCVSS v2 7.1EG 7.12009-03-26
Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custom SITE command containing shell metacharacters such as "&" (ampersand) in the middle of a…
- CVE-2008-6538MEDIUMCVSS v2 5.0EG 5.02009-03-30
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
- CVE-2008-6541MEDIUMCVSS v2 6.8EG 6.82009-03-30
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
- CVE-2008-6555HIGHCVSS v2 10.0EG 10.02009-03-30
cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command.
- CVE-2008-6556HIGHCVSS v2 10.0EG 10.02009-03-30
cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the whois command.
- CVE-2008-6557HIGHCVSS v2 10.0EG 10.02009-03-30
cgi-bin/webutil.pl in The Puppet Master WebUtil 2.7 allows remote attackers to execute arbitrary commands via shell metacharacters in the details command.
- CVE-2008-6558HIGHCVSS v2 7.2EG 7.22009-03-30
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program.
- CVE-2008-6559HIGHCVSS v2 7.2EG 7.22009-03-30
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. (dot dot) sequences that point to a directory containing a file whose name includes shell metacharacte…
- CVE-2008-6568MEDIUMCVSS v2 6.8EG 6.82009-03-31
Unrestricted file upload vulnerability in Yehe 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the envoyer feature. NOTE: the pr…
- CVE-2008-6662MEDIUMCVSS v2 4.3EG 4.32009-04-07
AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption.
- CVE-2008-6676MEDIUMCVSS v2 5.0EG 5.02009-04-08
QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message.
- CVE-2008-6684MEDIUMCVSS v2 6.8EG 6.82009-04-10
Unrestricted file upload vulnerability in editimage.php in Apartment Search Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a GIF header, then accessing this file via a direct r…
- CVE-2008-6702MEDIUMCVSS v2 5.0EG 5.02009-04-10
S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.
Map vulnerabilities like CWE-20 to your infrastructure
EchelonGraph correlates every CVE — across CWE-20 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →