CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-6217

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitrary web script or HTML via the plugins[file][id] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6213

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary SQL commands via the trg parameter.

    Published: 20 Feb 2009
    7.8
    High

    CVE-2008-6219

    Last Modified: 23 Apr 2026

    nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2008-6200

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Swiki 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the query string and (2) a new wiki entry.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) urun.asp, (2) admin/bayi_listele.asp, (3) admin/urun_grup_listele.asp, and (4) admin/urun_listele.asp.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6206

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    8.5
    High

    CVE-2008-6207

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in form_upload.php in PHPG Upload 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2008-6208

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in submitnews.php in e107 CMS 0.7.11 allows remote attackers to inject arbitrary web script or HTML via the (1) author_name, (2) itemtitle, and (3) item parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6209

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6210

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.

    Published: 20 Feb 2009
    6.8
    Medium

    CVE-2008-6201

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6204

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and sifre parameters to secure/admin/giris.asp, and (3) username and password to secure/admin/default.asp.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2008-6211

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhpForums.net mcGallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the lang parameter to (1) admin.php, (2) index.php, (3) sess.php, (4) stats.php, (5) detail.php, (6) resize.php, and (7) show.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2008-6212

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel_mese and (2) sel_anno parameters in a systems action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6203

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in adminler.asp in CoBaLT 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2008-6205

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) language, (2) order, and (3) filter parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    4.3
    Medium

    CVE-2009-2851

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.

    Published: 20 Feb 2009
    5
    Medium

    CVE-2009-0878

    Last Modified: 23 Apr 2026

    The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a map with a large (1) width or (2) height.

    Published: 20 Feb 2009
    4
    Medium

    CVE-2008-6199

    Last Modified: 23 Apr 2026

    2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6197

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6196

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the EASYSITE_BASE parameter to (1) browser.php, (2) image_editor.php and (3) skin_chooser.php in configuration/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Feb 2009
    7.8
    High

    CVE-2008-6195

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6198

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 20 Feb 2009
    7.5
    High

    CVE-2008-6179

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter, a different vector than CVE-2007-4069.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6182

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gallery parameter in a view action to index.php.

    Published: 19 Feb 2009
    7.8
    High

    CVE-2008-6183

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) d and (2) f parameters.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6184

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a catalogue action to index.php.

    Published: 19 Feb 2009
    5
    Medium

    CVE-2008-6185

    Last Modified: 23 Apr 2026

    NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 requests with a long PASS command.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6187

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6188

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6181

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the jid parameter to index.php.

    Published: 19 Feb 2009
    4.3
    Medium

    CVE-2008-6192

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified Portlets in Sun Java System Portal Server 7.0 and 7.1 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 19 Feb 2009
    5
    Medium

    CVE-2008-6193

    Last Modified: 23 Apr 2026

    Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Published: 19 Feb 2009
    7.8
    High

    CVE-2008-6194

    Last Modified: 23 Apr 2026

    Memory leak in the DNS server in Microsoft Windows allows remote attackers to cause a denial of service (memory consumption) via DNS packets. NOTE: this issue reportedly exists because of an incorrect fix for CVE-2007-3898.

    Published: 19 Feb 2009
    2.1
    Low

    CVE-2008-6191

    Last Modified: 23 Apr 2026

    Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 19 Feb 2009
    4.3
    Medium

    CVE-2008-6190

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in EEBCMS 0.95 allows remote attackers to inject arbitrary web script or HTML via the content parameter.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6180

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6189

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, which is not properly handled in database-pgsql.php.

    Published: 19 Feb 2009
    9
    Critical

    CVE-2008-6186

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via long (1) CWD and (2) MLST commands.

    Published: 19 Feb 2009
    6.8
    Medium

    CVE-2008-6177

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in LightBlog 9.8, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) username parameter to view_member.php, (2) username_post parameter to login.php, and the (3) Lightblog_username cookie parameter to check_user.php.

    Published: 19 Feb 2009
    Unknown

    CVE-2008-6176

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-6171. Reason: This candidate is a duplicate of CVE-2008-6171. Notes: All CVE users should reference CVE-2008-6171 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Feb 2009
    5
    Medium

    CVE-2008-6175

    Last Modified: 23 Apr 2026

    SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to the opendir SFTP command.

    Published: 19 Feb 2009
    5
    Medium

    CVE-2009-0647

    Last Modified: 23 Apr 2026

    msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown.

    Published: 19 Feb 2009
    6.8
    Medium

    CVE-2009-0648

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (aka Falt4 Extreme) RC4 allow remote attackers to hijack the authentication of administrators for requests that change passwords via the (1) edit and (2) edit_now actions.

    Published: 19 Feb 2009
    4.3
    Medium

    CVE-2008-6173

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 19 Feb 2009
    6.4
    Medium

    CVE-2008-4392

    Last Modified: 23 Apr 2026

    dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demonstrated by a spoofed A record in the Additional section of a response to a Start of Authority (SOA) query.

    Published: 19 Feb 2009
    6.8
    Medium

    CVE-2008-6172

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the img parameter.

    Published: 19 Feb 2009
    4.3
    Medium

    CVE-2008-6174

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inject arbitrary web script or HTML via the liste parameter.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6178

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094. NOTE: some of these details are obtained from third party information.

    Published: 19 Feb 2009
    4.3
    Medium

    CVE-2008-6168

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified argument, probably the search string.

    Published: 19 Feb 2009