CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-0703

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Feb 2009
    6.8
    Medium

    CVE-2009-0705

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Published: 23 Feb 2009
    7.5
    High

    CVE-2009-0704

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands via the search parameter in an advanced action.

    Published: 23 Feb 2009
    5
    Medium

    CVE-2009-0711

    Last Modified: 23 Apr 2026

    filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

    Published: 23 Feb 2009
    6.8
    Medium

    CVE-2009-0708

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) hijack the authentication of administrators via unknown vectors or (2) hijack the authentication of arbitrary users via vectors involving the profile page.

    Published: 23 Feb 2009
    4.3
    Medium

    CVE-2009-0710

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Feb 2009
    6.8
    Medium

    CVE-2009-0701

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) THEME_header and (2) THEME_footer parameters.

    Published: 23 Feb 2009
    7.5
    High

    CVE-2009-0706

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.

    Published: 23 Feb 2009
    7.5
    High

    CVE-2008-6237

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in software-description.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Feb 2009
    6.8
    Medium

    CVE-2008-6241

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php.

    Published: 23 Feb 2009
    7.5
    High

    CVE-2009-0702

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action to index.php.

    Published: 23 Feb 2009
    7.5
    High

    CVE-2009-0707

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL commands via the loginemail parameter (aka login field). NOTE: some of these details are obtained from third party information.

    Published: 23 Feb 2009
    7.5
    High

    CVE-2009-0709

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Feb 2009
    5.4
    Medium

    CVE-2009-0801

    Last Modified: 23 Apr 2026

    Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

    Published: 23 Feb 2009
    6.5
    Medium

    CVE-2009-0440

    Last Modified: 23 Apr 2026

    IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."

    Published: 22 Feb 2009
    6.5
    Medium

    CVE-2009-0672

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary SQL commands via the user_prefix parameter to modules.php.

    Published: 22 Feb 2009
    6.5
    Medium

    CVE-2009-0673

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary PHP code via the ID Field Name box in a yaCustomFields action to admin.php.

    Published: 22 Feb 2009
    6.5
    Medium

    CVE-2009-0677

    Last Modified: 23 Apr 2026

    avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP sequences in an element of the replacements array, which is processed by the preg_replace function with the eval switch, as specified in an element of the patterns array.

    Published: 22 Feb 2009
    5
    Medium

    CVE-2009-0678

    Last Modified: 23 Apr 2026

    images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, which reveals the installation path in an error message.

    Published: 22 Feb 2009
    4.3
    Medium

    CVE-2009-0679

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Feb 2009
    6
    Medium

    CVE-2009-0674

    Last Modified: 23 Apr 2026

    images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by sending requests with full pathnames in the aFonts array parameter, and then observing the error messages, which differ between existing and nonexistent pathnames.

    Published: 22 Feb 2009
    7.8
    High

    CVE-2009-0680

    Last Modified: 23 Apr 2026

    cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (device crash) via a crafted query string, as demonstrated using directory traversal sequences.

    Published: 22 Feb 2009
    5
    Medium

    CVE-2009-0753

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.

    Published: 22 Feb 2009
    7.5
    High

    CVE-2008-6236

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Feb 2009
    7.5
    High

    CVE-2008-6234

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 21 Feb 2009
    7.5
    High

    CVE-2008-6223

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the plancia parameter to crea.php.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6224

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the plancia parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6225

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbitrary SQL commands via the flight parameter. NOTE: the vendor has disputed this issue, stating "crazy hackers and so named Security companies [spread] out such false informations. Such scripts or versions [do not] exist.

    Published: 20 Feb 2009
    6.8
    Medium

    CVE-2008-6226

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the itemno parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6232

    Last Modified: 23 Apr 2026

    Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6233

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Five Dollar Scripts Drinks script allows remote attackers to execute arbitrary SQL commands via the recid parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6230

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6231

    Last Modified: 23 Apr 2026

    Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6228

    Last Modified: 23 Apr 2026

    Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6227

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters.

    Published: 20 Feb 2009
    3.5
    Low

    CVE-2008-6229

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.

    Published: 20 Feb 2009
    5
    Medium

    CVE-2008-6222

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the include_file parameter to index.php.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6220

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the pass parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6221

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter.

    Published: 20 Feb 2009
    5
    Medium

    CVE-2009-0659

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown impact via a STATS line with a long email field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    6.9
    Medium

    CVE-2009-0655

    Last Modified: 23 Apr 2026

    Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2009-0653

    Last Modified: 23 Apr 2026

    OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.

    Published: 20 Feb 2009
    6.9
    Medium

    CVE-2009-0656

    Last Modified: 23 Apr 2026

    Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image with a modified viewpoint that matches the posture of a stored image of the authorized notebook user.

    Published: 20 Feb 2009
    6.9
    Medium

    CVE-2009-0657

    Last Modified: 23 Apr 2026

    Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large number of images for which the viewpoint and lighting have been modified to match a stored image of the authorized notebook user.

    Published: 20 Feb 2009
    7.8
    High

    CVE-2009-0649

    Last Modified: 23 Apr 2026

    The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.

    Published: 20 Feb 2009
    10
    Critical

    CVE-2009-0650

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field. NOTE: some of these details are obtained from third party information.

    Published: 20 Feb 2009
    6.5
    Medium

    CVE-2009-0651

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Server 5.x, 6.0 before MP7 SP1, and 6.5 before 6.5.3.1 allows remote attackers to execute arbitrary code via unknown vectors related to "initial communications setup."

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6214

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in poll_results.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2008-6215

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to inject arbitrary web script or HTML via the OfertaID parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6216

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows remote attackers to execute arbitrary SQL commands via the OfertaID parameter.

    Published: 20 Feb 2009