CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6143

    Last Modified: 23 Apr 2026

    OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.

    Published: 16 Feb 2009
    6.8
    Medium

    CVE-2008-6146

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.

    Published: 16 Feb 2009
    5
    Medium

    CVE-2008-6147

    Last Modified: 23 Apr 2026

    ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/8690.mdb or (2) data/8690BAK.mdb.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6148

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6149

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cagtegory parameter in a story_lists action to index.php.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6151

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6152

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: this was originally reported for Lawyer Portal, which does not have a deptdisplay.asp file.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6153

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6145

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2009-0592

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ModName parameter to (1) admin_words.php, (2) admin_groups_reapir.php, (3) admin_smilies.php, (4) admin_ranks.php, (5) admin_styles.php, and (6) admin_users.php in admin/.

    Published: 16 Feb 2009
    6.5
    Medium

    CVE-2009-0593

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2009-0598

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Feb 2009
    6.8
    Medium

    CVE-2009-0596

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the TplSuffix parameter.

    Published: 16 Feb 2009
    6.8
    Medium

    CVE-2009-0597

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the benutzername parameter (aka Username field) in a login action.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6142

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php.

    Published: 16 Feb 2009
    4.3
    Medium

    CVE-2008-6144

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-3029.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6150

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 16 Feb 2009
    4.3
    Medium

    CVE-2009-0594

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 16 Feb 2009
    5.1
    Medium

    CVE-2009-0595

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter.

    Published: 16 Feb 2009
    5.8
    Medium

    CVE-2009-0652

    Last Modified: 23 Apr 2026

    The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

    Published: 16 Feb 2009
    5.1
    Medium

    CVE-2009-0654

    Last Modified: 23 Apr 2026

    Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."

    Published: 16 Feb 2009
    1.9
    Low

    CVE-2010-2387

    Last Modified: 11 Apr 2025

    vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.

    Published: 15 Feb 2009
    7.5
    High

    CVE-2008-6134

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Feb 2009
    5
    Medium

    CVE-2008-6139

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.

    Published: 14 Feb 2009
    5
    Medium

    CVE-2008-6141

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.

    Published: 14 Feb 2009
    7.5
    High

    CVE-2008-6137

    Last Modified: 23 Apr 2026

    EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.

    Published: 14 Feb 2009
    7.5
    High

    CVE-2008-6138

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.

    Published: 14 Feb 2009
    4.3
    Medium

    CVE-2008-6135

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Feb 2009
    7.5
    High

    CVE-2008-6136

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors.

    Published: 14 Feb 2009
    5
    Medium

    CVE-2008-6140

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to cause a denial of service (crash) via unspecified vectors.

    Published: 14 Feb 2009
    7.8
    High

    CVE-2009-1389

    Last Modified: 23 Apr 2026

    Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet.

    Published: 14 Feb 2009
    5
    Medium

    CVE-2008-6126

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) page parameter to index.php, a different vector than CVE-2008-3589.

    Published: 13 Feb 2009
    4.3
    Medium

    CVE-2008-6129

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in print.php in moziloWiki 1.0.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Published: 13 Feb 2009
    4.3
    Medium

    CVE-2008-6130

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in moziloWiki 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) action and (2) page parameters.

    Published: 13 Feb 2009
    6
    Medium

    CVE-2008-6131

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 13 Feb 2009
    7.5
    High

    CVE-2008-6133

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3942.

    Published: 13 Feb 2009
    6.8
    Medium

    CVE-2008-6128

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 13 Feb 2009
    4.3
    Medium

    CVE-2008-6127

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) index.php, (3) cat and (4) file parameters to (b) download.php, (5) gal parameter to gallery.php, and the (6) URL to admin/login.php.

    Published: 13 Feb 2009
    6.8
    Medium

    CVE-2008-6132

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter.

    Published: 13 Feb 2009
    4.3
    Medium

    CVE-2009-0575

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to node titles. NOTE: some of these details are obtained from third party information.

    Published: 13 Feb 2009
    6.2
    Medium

    CVE-2009-0360

    Last Modified: 23 Apr 2026

    Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.

    Published: 13 Feb 2009
    10
    Critical

    CVE-2009-0216

    Last Modified: 23 Apr 2026

    GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.

    Published: 13 Feb 2009
    7.8
    High

    CVE-2009-0576

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Directory Server 5.2 p6 and earlier, and Enterprise Edition 5, allows remote attackers to cause a denial of service (daemon crash) via crafted LDAP requests.

    Published: 13 Feb 2009
    4.6
    Medium

    CVE-2009-0361

    Last Modified: 23 Apr 2026

    Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.

    Published: 13 Feb 2009
    2.1
    Low

    CVE-2009-0503

    Last Modified: 23 Apr 2026

    IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.

    Published: 13 Feb 2009
    5.1
    Medium

    CVE-2009-0570

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter. NOTE: some of these details are obtained from third party information.

    Published: 13 Feb 2009
    5
    Medium

    CVE-2009-0571

    Last Modified: 23 Apr 2026

    admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the backup directory.

    Published: 13 Feb 2009
    5.1
    Medium

    CVE-2009-0572

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.

    Published: 13 Feb 2009
    4.3
    Medium

    CVE-2009-0573

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to cmdrequest/Login.fwx and the (2) search parameter to Grid.fwx.

    Published: 13 Feb 2009
    7.5
    High

    CVE-2009-0574

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.

    Published: 13 Feb 2009