CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-6646

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6647

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6648

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6649

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 7 Apr 2009
    5
    Medium

    CVE-2008-6650

    Last Modified: 23 Apr 2026

    del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628.

    Published: 7 Apr 2009
    10
    Critical

    CVE-2008-6651

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6652

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6656

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6644

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6631

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user, different vectors than CVE-2008-0679.

    Published: 7 Apr 2009
    6.8
    Medium

    CVE-2008-6636

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_skins parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6637

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) school and (2) email parameters.

    Published: 7 Apr 2009
    8.8
    High

    CVE-2008-6638

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6640

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Apr 2009
    6.5
    Medium

    CVE-2008-6641

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6645

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6654

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_results.php in InfoBiz Server allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Published: 7 Apr 2009
    5.8
    Medium

    CVE-2009-0844

    Last Modified: 23 Apr 2026

    The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.

    Published: 7 Apr 2009
    10
    Critical

    CVE-2009-0846

    Last Modified: 23 Apr 2026

    The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2009-0847

    Last Modified: 23 Apr 2026

    The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6624

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6625

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6626

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6623

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 6 Apr 2009
    Unknown

    CVE-2008-6628

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-6268. Reason: This candidate is a duplicate of CVE-2008-6268. Notes: All CVE users should reference CVE-2008-6268 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6627

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6622

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2008-6629

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6615

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2008-6616

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Apr 2009
    6.8
    Medium

    CVE-2008-6617

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6618

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in class/MessageReply.php.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6614

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field).

    Published: 6 Apr 2009
    6.8
    Medium

    CVE-2008-6619

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2008-6620

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in javascript/editor/editor/filemanager/browser/mcpuk/connectors/php/connector.php in GraFX miniCWB 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errcontext, (2) _GET, (3) _POST, (4) _SESSION, (5) _SERVER, and (6) fckphp_config[Debug_SERVER] parameters.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2009-1248

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme_directory parameter to (1) container.php and (2) header.php in themes/.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2009-1246

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) row_mysql_blocks_center_down[file] parameter to includes/block_center_down.php; (2) row_mysql_blocks_center_top[file] includes/parameter to block_center_top.php; (3) row_mysql_blocks_left[file] parameter to includes/block_left.php; (4) row_mysql_blocks_right[file] parameter to includes/block_right.php; and row_mysql_bloginfo[theme] parameter to (5) includes/window_down.php and (6) includes/window_top.php.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2009-1245

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the insert_to_pastebin function in php/cccp-admin/inc/functions.php in CCCP Community Clan Portal Pastebin before 2.80 allow remote attackers to execute arbitrary SQL commands via the (1) subject, (2) language, and (3) nickname parameters to php/cccp-pages/submit.php. NOTE: some of these details are obtained from third party information.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6613

    Last Modified: 23 Apr 2026

    uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2008-6609

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpcksec.php in Stefan Ott phpcksec 0.2 allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Published: 6 Apr 2009
    6.4
    Medium

    CVE-2008-6610

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in phpcksec.php in Stefan Ott phpcksec 0.2.0 allows remote attackers to list arbitrary directories and read arbitrary files via a full pathname in the file parameter.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6611

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Apr 2009
    6.8
    Medium

    CVE-2008-6612

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2009-1249

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2009-1247

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 6 Apr 2009
    7.2
    High

    CVE-2009-1147

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local users to gain privileges via unknown vectors.

    Published: 6 Apr 2009
    9.3
    Critical

    CVE-2009-0909

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435.

    Published: 6 Apr 2009
    4.6
    Medium

    CVE-2008-4916

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and earlier 2.x versions; VMware ACE before 1.0.8 build 125922, and 2.5.1 and earlier 2.x versions; VMware Server 1.x before 1.0.8 build 126538 and 2.0.x before 2.0.1 build 156745; VMware Fusion before 2.0.1; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to cause a denial of service (host OS crash) via unknown vectors.

    Published: 6 Apr 2009
    2.1
    Low

    CVE-2009-0518

    Last Modified: 23 Apr 2026

    VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.

    Published: 6 Apr 2009