CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2008-6423

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6435

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[home], (2) lang[admin_menu], and (3) lang[admin_menu_page_overview] parameters to cms/includes/header.inc.php; and the (4) lang[login_username] and (5) lang[login_password] parameters to cms/includes/login.inc.php.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6439

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6401

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6402

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6403

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6407

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the framefile parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6408

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in the framefile parameter.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6406

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in DataLife Engine (DLE) 7.2 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6413

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Answers module 5.x-1.x-dev and possibly other 5.x versions, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a Simple Answer to a question.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6414

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Published: 6 Mar 2009
    10
    Critical

    CVE-2008-6415

    Last Modified: 23 Apr 2026

    Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6412

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6405

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6410

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6404

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6409

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6411

    Last Modified: 23 Apr 2026

    Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.

    Published: 6 Mar 2009
    5
    Medium

    CVE-2009-0027

    Last Modified: 23 Apr 2026

    The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2009-0781

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2009-0830

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in QuoteBook allows remote attackers to inject arbitrary web script or HTML via the (1) QuoteName and (2) QuoteText parameters to quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Mar 2009
    4.3
    Medium

    CVE-2008-6400

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) search.php. NOTE: some of these details are obtained from third party information.

    Published: 5 Mar 2009
    5
    Medium

    CVE-2009-0826

    Last Modified: 23 Apr 2026

    BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.

    Published: 5 Mar 2009
    6
    Medium

    CVE-2009-0831

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.

    Published: 5 Mar 2009
    7.5
    High

    CVE-2009-0832

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.

    Published: 5 Mar 2009
    6.4
    Medium

    CVE-2008-6399

    Last Modified: 24 Apr 2026

    Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.

    Published: 5 Mar 2009
    7.5
    High

    CVE-2009-0829

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Mar 2009
    9.3
    Critical

    CVE-2009-0833

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field. NOTE: some of these details are obtained from third party information.

    Published: 5 Mar 2009
    5
    Medium

    CVE-2009-0827

    Last Modified: 23 Apr 2026

    PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.

    Published: 5 Mar 2009
    5
    Medium

    CVE-2009-0828

    Last Modified: 23 Apr 2026

    QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.

    Published: 5 Mar 2009
    7.8
    High

    CVE-2009-0619

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000.

    Published: 5 Mar 2009
    4.3
    Medium

    CVE-2009-0814

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.

    Published: 5 Mar 2009
    5
    Medium

    CVE-2009-0815

    Last Modified: 23 Apr 2026

    The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.

    Published: 5 Mar 2009
    4.3
    Medium

    CVE-2009-0816

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.

    Published: 5 Mar 2009
    7.5
    High

    CVE-2009-0820

    Last Modified: 23 Apr 2026

    Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.

    Published: 5 Mar 2009
    5
    Medium

    CVE-2009-0821

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.

    Published: 5 Mar 2009
    3.5
    Low

    CVE-2009-0818

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the taxonomy_theme_admin_table_builder function (taxonomy_theme_admin.inc) in Taxonomy Theme module before 5.x-1.2, a module for Drupal, allows remote authenticated users with the "administer taxonomy" permission, or the ability to create pages when tagging is enabled, to inject arbitrary web script or HTML via the Vocabulary name (name parameter) to index.php. NOTE: some of these details are obtained from third party information.

    Published: 5 Mar 2009
    4
    Medium

    CVE-2009-0819

    Last Modified: 23 Apr 2026

    sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.

    Published: 5 Mar 2009
    9.3
    Critical

    CVE-2009-0367

    Last Modified: 23 Apr 2026

    The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.

    Published: 5 Mar 2009
    9.3
    Critical

    CVE-2009-0813

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters.

    Published: 5 Mar 2009
    3.5
    Low

    CVE-2009-0817

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.

    Published: 5 Mar 2009
    7.5
    High

    CVE-2008-6394

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.

    Published: 4 Mar 2009
    4.4
    Medium

    CVE-2008-6397

    Last Modified: 23 Apr 2026

    rlatex in AlcoveBook sgml2x 1.0.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 4 Mar 2009
    6.9
    Medium

    CVE-2008-6398

    Last Modified: 23 Apr 2026

    sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

    Published: 4 Mar 2009
    6.5
    Medium

    CVE-2009-0806

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors.

    Published: 4 Mar 2009
    7.5
    High

    CVE-2009-0807

    Last Modified: 23 Apr 2026

    zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.

    Published: 4 Mar 2009
    7.5
    High

    CVE-2009-0808

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Mar 2009
    4.3
    Medium

    CVE-2009-0805

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a module for XOOPS, allows remote attackers to inject arbitrary web script or HTML via the event_id parameter in index.php.

    Published: 4 Mar 2009
    9.3
    Critical

    CVE-2009-0811

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.

    Published: 4 Mar 2009
    4.3
    Medium

    CVE-2008-6396

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Mar 2009