CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6941

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6942

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.

    Published: 12 Aug 2009
    4.3
    Medium

    CVE-2008-6946

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via the project Name, which is not properly handled when the administrator performs an editform action, related to admin.php.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2008-6947

    Last Modified: 23 Apr 2026

    Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated with the added mode in a users action to admin.php.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6948

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and using a text/plain MIME type, then accessing it via a direct request to the file in files/, related to (1) the showproject action in managefile.php or (2) the Messages feature.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2008-6950

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

    Published: 12 Aug 2009
    9
    Critical

    CVE-2008-6954

    Last Modified: 23 Apr 2026

    The web interface (CobblerWeb) in Cobbler before 1.2.9 allows remote authenticated users to execute arbitrary Python code in cobblerd by editing a Cheetah kickstart template to import arbitrary Python modules.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2008-6955

    Last Modified: 23 Apr 2026

    mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2008-6957

    Last Modified: 23 Apr 2026

    member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6958

    Last Modified: 23 Apr 2026

    wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.

    Published: 12 Aug 2009
    9.3
    Critical

    CVE-2008-6959

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attackers to overwrite arbitrary files via the SaveLastError method. NOTE: this might be related to CVE-2008-1647.

    Published: 12 Aug 2009
    4.9
    Medium

    CVE-2009-1427

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6943

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2008-6951

    Last Modified: 23 Apr 2026

    MauryCMS 0.53.2 and earlier does not require administrative authentication for Editors/fckeditor/editor/filemanager/browser/default/browser.html, which allows remote attackers to upload arbitrary files via a direct request.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6956

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Aug 2009
    5
    Medium

    CVE-2008-6960

    Last Modified: 23 Apr 2026

    download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6944

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/.

    Published: 12 Aug 2009
    4.3
    Medium

    CVE-2008-6945

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the country-select widget, or (3) possibly the value specifier when used in the UserTag feature.

    Published: 12 Aug 2009
    6.8
    Medium

    CVE-2008-6949

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators for requests that (1) submit or edit a new project, or (2) upload files to a project, or (3) attach files to messages via unknown vectors. NOTE: these issues can be leveraged with other vulnerabilities to create remote attack vectors that do not require authentication.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2008-6952

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 12 Aug 2009
    9.3
    Critical

    CVE-2008-6953

    Last Modified: 23 Apr 2026

    Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long oovoo: URI.

    Published: 12 Aug 2009
    7.8
    High

    CVE-2009-2726

    Last Modified: 23 Apr 2026

    The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP.

    Published: 12 Aug 2009
    6.8
    Medium

    CVE-2009-3490

    Last Modified: 23 Apr 2026

    GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 12 Aug 2009
    6.8
    Medium

    CVE-2009-2964

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php.

    Published: 12 Aug 2009
    7.5
    High

    CVE-2009-2417

    Last Modified: 23 Apr 2026

    lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 12 Aug 2009
    6.5
    Medium

    CVE-2008-6930

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/.

    Published: 11 Aug 2009
    6.5
    Medium

    CVE-2008-6931

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images.

    Published: 11 Aug 2009
    7.5
    High

    CVE-2008-6932

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in send/files/.

    Published: 11 Aug 2009
    5
    Medium

    CVE-2008-6933

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via a .. (dot dot) in the list parameter.

    Published: 11 Aug 2009
    4.3
    Medium

    CVE-2008-6938

    Last Modified: 23 Apr 2026

    Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.

    Published: 11 Aug 2009
    10
    Critical

    CVE-2008-6935

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.

    Published: 11 Aug 2009
    6.5
    Medium

    CVE-2008-6928

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/.

    Published: 11 Aug 2009
    6.5
    Medium

    CVE-2008-6929

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/.

    Published: 11 Aug 2009
    7.5
    High

    CVE-2008-6934

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information.

    Published: 11 Aug 2009
    9.3
    Critical

    CVE-2008-6936

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.

    Published: 11 Aug 2009
    10
    Critical

    CVE-2008-6937

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Aug 2009
    4.3
    Medium

    CVE-2009-2739

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 11 Aug 2009
    4.3
    Medium

    CVE-2009-2738

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.

    Published: 11 Aug 2009
    6.8
    Medium

    CVE-2009-2735

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 11 Aug 2009
    4.3
    Medium

    CVE-2009-2705

    Last Modified: 23 Apr 2026

    CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.

    Published: 11 Aug 2009
    4.3
    Medium

    CVE-2009-2704

    Last Modified: 23 Apr 2026

    CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).

    Published: 11 Aug 2009
    6.5
    Medium

    CVE-2009-2736

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action.

    Published: 11 Aug 2009
    7.8
    High

    CVE-2009-0687

    Last Modified: 23 Apr 2026

    The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.

    Published: 11 Aug 2009
    6.8
    Medium

    CVE-2009-3765

    Last Modified: 23 Apr 2026

    mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 11 Aug 2009
    7.5
    High

    CVE-2009-3042

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.

    Published: 11 Aug 2009
    4.4
    Medium

    CVE-2009-1297

    Last Modified: 23 Apr 2026

    iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.

    Published: 11 Aug 2009
    9.3
    Critical

    CVE-2009-2195

    Last Modified: 23 Apr 2026

    Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.

    Published: 11 Aug 2009
    9.3
    Critical

    CVE-2009-2727

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15.

    Published: 10 Aug 2009
    4.3
    Medium

    CVE-2008-6924

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register parameters.

    Published: 10 Aug 2009
    6.8
    Medium

    CVE-2008-6926

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.

    Published: 10 Aug 2009