CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-6087

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2008-6089

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2008-6090

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6086

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3355.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2009-0470

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2009-0471

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2009-0472

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2002-2428

    Last Modified: 23 Apr 2026

    webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2002-2427

    Last Modified: 23 Apr 2026

    The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2003-1568

    Last Modified: 23 Apr 2026

    GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2003-1569

    Last Modified: 23 Apr 2026

    GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2002-2429

    Last Modified: 23 Apr 2026

    webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2002-2431

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6075

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL commands via the kid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6076

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 6 Feb 2009
    6.5
    Medium

    CVE-2008-6077

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2008-6080

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6081

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2008-6082

    Last Modified: 23 Apr 2026

    Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6083

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2008-6084

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6078

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a pms action to index.php.

    Published: 6 Feb 2009
    5.1
    Medium

    CVE-2008-6074

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter.

    Published: 6 Feb 2009
    7.6
    High

    CVE-2008-6085

    Last Modified: 23 Apr 2026

    Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer overflow.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0460

    Last Modified: 23 Apr 2026

    Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0456

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in examples/example_clientside_javascript.php in patForms, as used in Sourdough 0.3.5, allows remote attackers to execute arbitrary PHP code via a URL in the neededFiles[patForms] parameter.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0457

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter to admin/case.php in the (1) Contact_Plus and (2) Reviews modules, and (3) the module_name parameter to admin/includes/FANCYNLOptions.php in the Fancy_NewsLetter module.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0458

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0462

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to execute arbitrary SQL commands via (1) the txtEmail parameter (aka E-MAIL field) or (2) the txtPassword parameter (aka password field) to customer_login.asp. NOTE: some of these details are obtained from third party information.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2009-0463

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Published: 6 Feb 2009
    5.1
    Medium

    CVE-2009-0464

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Published: 6 Feb 2009
    9.3
    Critical

    CVE-2009-0465

    Last Modified: 23 Apr 2026

    The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the intended .box filename extension, as demonstrated by a C:\boot.ini\0 argument.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0461

    Last Modified: 23 Apr 2026

    Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0469

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vectors.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2009-0468

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown the server, (2) send ping packets, (3) enable network services, (4) configure a proxy server, and (5) modify other settings via parameters in the query string.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2009-0467

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject arbitrary web script or HTML via the proxy parameter in a deny_log manage action.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2009-0459

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2009-0466

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6068

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2008-6069

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in e107chat.php in the eChat plugin 4.2 for e107, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.

    Published: 6 Feb 2009
    4.9
    Medium

    CVE-2008-6073

    Last Modified: 23 Apr 2026

    StorageCrypt 2.0.1 does not properly encrypt disks, which allows local users to obtain sensitive information via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Feb 2009
    2.1
    Low

    CVE-2009-0601

    Last Modified: 23 Apr 2026

    Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2009-0417

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the AgaviWebRouting::gen(null) method in Agavi 0.11 before 0.11.6 and 1.0 before 1.0.0 beta 8 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with certain characters that are not properly handled by web browsers that do not strictly follow RFC 3986, such as Internet Explorer 6 and 7.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2009-0599

    Last Modified: 23 Apr 2026

    Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file.

    Published: 6 Feb 2009
    4.3
    Medium

    CVE-2009-0600

    Last Modified: 23 Apr 2026

    Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2009-0441

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter, a different vector than CVE-2008-4138.

    Published: 5 Feb 2009
    6.8
    Medium

    CVE-2009-0442

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0447

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the user parameter (aka UserName field) or (2) the pass parameter (aka Pass field) to (a) admin/admin.asp or (b) the default URI under admin/. NOTE: some of these details are obtained from third party information.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0448

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the synTarget parameter.

    Published: 5 Feb 2009
    7.2
    High

    CVE-2009-0449

    Last Modified: 23 Apr 2026

    Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call.

    Published: 5 Feb 2009