CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-7058

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and force a logout via adminpanel/logout.php.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7059

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in One-News Beta 2 allows remote attackers to execute arbitrary SQL commands via the q parameter.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7060

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in One-News Beta 2 allow remote attackers to inject arbitrary HTML and web script via the (1) title or (2) content parameters in a news item to add.php, and the (3) itemnum, (4) author, or (5) comment parameters in a comment to index.php. NOTE: vectors 1 and 2 require user authentication.

    Published: 24 Aug 2009
    5.1
    Medium

    CVE-2008-7054

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home parameters to modules/diary/showdiary.php; (3) admin_home, (4) gsLanguage, and (5) language_home parameters to modules/diary/showdiarydetail.php; (6) gsLanguage and (7) language_home parameters to modules/diary/submit_diary.php; (8) admin_home parameter to modules/news/news_summary.php; (9) nLink, (10) gsLanguage, and (11) language_home parameters to modules/news/inlinenews.php; and possibly other unspecified vectors in (12) diary/showeventlist.php, (13) gallery/showgallery.php, (14) reviews/showreviews.php, (15) gallery/showgallerydetails.php, (16) reviews/showreviewsdetails.php, (17) news/shownewsdetails.php, (18) gallery/submit_gallery.php, (19) guestbook/submit_guestbook.php, (20) reviews/submit_reviews.php, (21) news/submit_news.php, (22) diary/inlineeventlist.php, and (23) news/archivednews_summary.php in modules/, related to the lack of directory traversal protection in modules/moduleSec.php.

    Published: 24 Aug 2009
    5.1
    Medium

    CVE-2008-7055

    Last Modified: 23 Apr 2026

    module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7061

    Last Modified: 23 Apr 2026

    The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title attribute, which is not properly handled when displaying a tooltip, a different vulnerability than CVE-2008-6994. NOTE: there is inconsistent information about the environments under which this issue exists.

    Published: 24 Aug 2009
    5
    Medium

    CVE-2009-2955

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

    Published: 24 Aug 2009
    5
    Medium

    CVE-2009-2954

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

    Published: 24 Aug 2009
    5
    Medium

    CVE-2009-2956

    Last Modified: 23 Apr 2026

    The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files.

    Published: 24 Aug 2009
    4.9
    Medium

    CVE-2009-2952

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local users to cause a denial of service (panic) via unknown vectors.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2009-2951

    Last Modified: 23 Apr 2026

    Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine cleartext passwords.

    Published: 24 Aug 2009
    6
    Medium

    CVE-2008-7029

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in usercp.php in AlilG Application AliBoard Beta allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in uploads/avatars/.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7030

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

    Published: 24 Aug 2009
    10
    Critical

    CVE-2008-7031

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151.

    Published: 24 Aug 2009
    6.8
    Medium

    CVE-2008-7032

    Last Modified: 23 Apr 2026

    Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7036

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7037

    Last Modified: 23 Apr 2026

    The Sidebar gadget in ITN News Gadget (aka ITN Hub Gadget) 1.06 for Windows Vista, and possibly other versions before 1.23, allows remote web servers or man-in-the-middle attackers to execute arbitrary commands via script in a short_title response.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7042

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7043

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter. NOTE: this can be leveraged to modify cookies and conduct session fixation attacks.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7044

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.

    Published: 24 Aug 2009
    6.4
    Medium

    CVE-2008-7045

    Last Modified: 23 Apr 2026

    AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7050

    Last Modified: 23 Apr 2026

    The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required arguments, which always triggers an authentication failure, and (2) returns true instead of false when an authentication failure occurs, which allows remote attackers to bypass authentication and gain privileges with an arbitrary password.

    Published: 24 Aug 2009
    6.5
    Medium

    CVE-2008-7052

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7038

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2003-1574

    Last Modified: 23 Apr 2026

    TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information.

    Published: 24 Aug 2009
    6.4
    Medium

    CVE-2008-7046

    Last Modified: 23 Apr 2026

    AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7033

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than CVE-2008-2568. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7034

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in kernel/smarty/Smarty.class.php in PHPEcho CMS 2.0 rc3 allows remote attackers to execute arbitrary PHP code via a URL in unspecified vectors that modify the _smarty_compile_path variable in the fetch function.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7035

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in an unspecified component in Simple Machines phpRaider 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the resistance field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7039

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/comments.php in Gelato CMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter in a comment. NOTE: some of these details are obtained from third party information.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7040

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7041

    Last Modified: 23 Apr 2026

    AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7047

    Last Modified: 23 Apr 2026

    NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct request to admin/home.asp.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7048

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NatterChat 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) txtUsername parameter to registerDo.asp, as invoked from register.asp, or (2) txtRoomName parameter to room_new.asp. NOTE: these issues might be resultant from XSS in SQL error messages.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7049

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by home.asp. NOTE: due to lack of details, it is not clear whether this is related to CVE-2004-2206.

    Published: 24 Aug 2009
    7.5
    High

    CVE-2008-7051

    Last Modified: 23 Apr 2026

    AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.

    Published: 24 Aug 2009
    7.8
    High

    CVE-2009-2698

    Last Modified: 23 Apr 2026

    The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket.

    Published: 24 Aug 2009
    4.9
    Medium

    CVE-2009-3002

    Last Modified: 23 Apr 2026

    The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.

    Published: 23 Aug 2009
    4.9
    Medium

    CVE-2009-3001

    Last Modified: 23 Apr 2026

    The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.

    Published: 23 Aug 2009
    7.8
    High

    CVE-2009-2931

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2929

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner, (9) admin_email, (10) default_language, and (11) db_host parameters to cms/index.php; and the (12) cmd, (13) s_dir, (14) minutes, (15) s_mask, (16) test3_mp, (17) test15_file1, (18) submit, (19) brute_method, (20) ftp_server_port, (21) userfile14, (22) subj, (23) mysql_l, (24) action, and (25) userfile1 parameters to cms/frontpage_ception.php. NOTE: some of these parameters may be applicable only in nonstandard versions of the product, and cms/frontpage_ception.php may be cms/frontpage_caption.php in all released versions.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2009-2928

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2009-2930

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2009-2932

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (Java) 7.0 allows remote attackers to inject arbitrary web script or HTML via the TModel Key field.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2933

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in Piwigo before 2.0.3 allows remote attackers to execute arbitrary SQL commands via the items_number parameter.

    Published: 21 Aug 2009
    9.3
    Critical

    CVE-2009-2934

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attackers to execute arbitrary code via a long string in a (1) .pls or (2) .pl playlist file.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2927

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2926

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.

    Published: 21 Aug 2009
    2.6
    Low

    CVE-2009-1879

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 21 Aug 2009
    3.3
    Low

    CVE-2009-1154

    Last Modified: 23 Apr 2026

    Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.

    Published: 21 Aug 2009