CWE-98
1,295 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
CVEs (1,295)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. |
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions. |
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to ind...Show more |
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and exe...Show more |
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that t...Show more |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through...Show more |
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. |
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. |
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. |
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. |
Unauthenticated Local File Inclusion in Etude <= 1.6 versions. |
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions. |
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions. |
Unauthenticated Local File Inclusion in Skyward <= 1.10 versions. |
Unauthenticated Local File Inclusion in Granola <= 1.13 versions. |
Unauthenticated Local File Inclusion in Gamic <= 1.15 versions. |
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions. |
Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. |
Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. |