CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2008-6048

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in TangoCMS before 2.2.0 allow remote attackers to hijack the authentication of administrators.

    Published: 4 Feb 2009
    4.3
    Medium

    CVE-2009-0502

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php in Snoopy 1.2.3, as used in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4, allows remote attackers to inject arbitrary web script or HTML via an HTML block, which is not properly handled when the "Login as" feature is used to visit a MyMoodle or Blog page.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2009-0501

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct "brute force attacks on user accounts" via unknown vectors.

    Published: 4 Feb 2009
    4.3
    Medium

    CVE-2009-0500

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.

    Published: 4 Feb 2009
    6.4
    Medium

    CVE-2009-0499

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to delete unauthorized forum posts via a link or IMG tag to post.php.

    Published: 4 Feb 2009
    4
    Medium

    CVE-2009-0362

    Last Modified: 23 Apr 2026

    filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.

    Published: 4 Feb 2009
    10
    Critical

    CVE-2009-0414

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.

    Published: 3 Feb 2009
    6.9
    Medium

    CVE-2009-0416

    Last Modified: 23 Apr 2026

    The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /var/tmp/key.pem, (2) /var/tmp/cert.pem, and (3) /var/tmp/ssl.cnf temporary files.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0412

    Last Modified: 23 Apr 2026

    The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.

    Published: 3 Feb 2009
    4.7
    Medium

    CVE-2008-4914

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial of service (host crash) via a snapshot with a malformed VMDK delta disk.

    Published: 3 Feb 2009
    5
    Medium

    CVE-2009-0276

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0399

    Last Modified: 23 Apr 2026

    Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2009-0400

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0405

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0407

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 3 Feb 2009
    6
    Medium

    CVE-2009-0408

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in osCommerce 2.2 RC 2a allows remote attackers to hijack the authentication of administrators.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2009-0409

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0406

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Feb 2009
    5
    Medium

    CVE-2009-0274

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow remote attackers to obtain sensitive information via a crafted URL, related to conversion of POST requests to GET requests.

    Published: 3 Feb 2009
    10
    Critical

    CVE-2009-0410

    Last Modified: 23 Apr 2026

    Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.

    Published: 3 Feb 2009
    10
    Critical

    CVE-2009-0183

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request.

    Published: 3 Feb 2009
    9.3
    Critical

    CVE-2009-0184

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0401

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browsecats.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0402

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in client/new_account.php in Domain Technologie Control (DTC) before 0.29.16 allows remote attackers to execute arbitrary SQL commands via the (1) familyname, (2) christname, (3) company_name, (4) is_company, (5) email, (6) phone, (7) fax, (8) addr1, (9) addr2, (10) addr3, (11) zipcode, (12) city, (13) state, (14) country, and (15) vat_num parameters.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0403

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 3 Feb 2009
    4.3
    Medium

    CVE-2009-0404

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) expressions in the style attribute, which is processed by Internet Explorer 7.

    Published: 3 Feb 2009
    5
    Medium

    CVE-2009-0411

    Last Modified: 23 Apr 2026

    Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6028

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter in a subject action.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6032

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6033

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Feb 2009
    4.3
    Medium

    CVE-2008-6034

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the atkaction parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Feb 2009
    4.3
    Medium

    CVE-2008-6035

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2-STABLE allows remote attackers to inject arbitrary web script or HTML via the atknodetype parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6036

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mj_config[src_path] parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6038

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.

    Published: 3 Feb 2009
    4.3
    Medium

    CVE-2008-6041

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Index.asp in Dataspade 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ViewName, (2) TableName, (3) OrderBy, and (4) FilterField parameters.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6042

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.

    Published: 3 Feb 2009
    4.3
    Medium

    CVE-2008-6044

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2008-6045

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6040

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Arcadem Pro 2.700 through 2.802 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter, probably related to includes/articleblock.php.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6043

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and unspecified other components. NOTE: some of these details are obtained from third party information.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2008-6025

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6026

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tienda.php in BlueCUBE CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2008-6029

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6030

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL commands via (1) the job parameter to index.php in the search module or (2) the news_id parameter to index.php.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6031

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported that 2.34 is also vulnerable.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2008-6037

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the v parameter.

    Published: 3 Feb 2009
    4.3
    Medium

    CVE-2008-6027

    Last Modified: 23 Mar 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2008-6039

    Last Modified: 23 Mar 2026

    Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 3 Feb 2009
    6.8
    Medium

    CVE-2009-0392

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.

    Published: 3 Feb 2009
    7.8
    High

    CVE-2009-0396

    Last Modified: 23 Apr 2026

    The Sony Ericsson W910i, W660i, K618i, K610i, Z610i, K810i, K660i, W880i, and K530i phones allow remote attackers to cause a denial of service (device reboot or hang-up) via a malformed WAP Push packet to (1) SMS or (2) UDP port 2948.

    Published: 3 Feb 2009