CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-5816

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.

    Published: 2 Jan 2009
    10
    Critical

    CVE-2008-5810

    Last Modified: 23 Apr 2026

    WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used during temporary session data cleanup, possibly related to (1) directory names, (2) template names, and (3) session IDs.

    Published: 2 Jan 2009
    4.3
    Medium

    CVE-2008-5808

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Six Apart Movable Type Enterprise (MTE) 1.x before 1.56; Movable Type (MT) 3.x before 3.38; and Movable Type, Movable Type Open Source (MTOS), and Movable Type Enterprise 4.x before 4.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to "application management."

    Published: 2 Jan 2009
    7.5
    High

    CVE-2008-5813

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Jan 2009
    10
    Critical

    CVE-2008-5812

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectors.

    Published: 2 Jan 2009
    9.3
    Critical

    CVE-2006-7236

    Last Modified: 23 Apr 2026

    The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified other impact via escape sequences.

    Published: 2 Jan 2009
    7.5
    High

    CVE-2008-5815

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Jan 2009
    6.8
    Medium

    CVE-2008-5817

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in a sign_in action.

    Published: 2 Jan 2009
    6.8
    Medium

    CVE-2008-5818

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lg parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Jan 2009
    5.8
    Medium

    CVE-2008-5809

    Last Modified: 23 Apr 2026

    futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, which makes it easier for remote attackers to hijack sessions, and obtain sensitive information about analysis results, via a modified id.

    Published: 2 Jan 2009
    9.3
    Critical

    CVE-2009-0490

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.

    Published: 2 Jan 2009
    4.3
    Medium

    CVE-2008-5799

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Wir ber uns (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Dec 2008
    6.8
    Medium

    CVE-2008-5793

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.

    Published: 31 Dec 2008
    6.8
    Medium

    CVE-2008-5792

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: the researcher also points out the analogous directory traversal issue.

    Published: 31 Dec 2008
    10
    Critical

    CVE-2008-5791

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in PrestaShop e-Commerce Solution before 1.1 Beta 2 (aka 1.1.0.1) have unknown impact and attack vectors, related to the (1) bankwire module, (2) cheque module, and other components.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5790

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5789

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.

    Published: 31 Dec 2008
    4.3
    Medium

    CVE-2008-5786

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Silva Find extension 1.1.5 and earlier in Silva 1.x before 1.6.3.2, Silva 2.0 before 2.0.12.2, and Silva 2.1 before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the fulltext parameter.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5782

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5783

    Last Modified: 23 Apr 2026

    admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

    Published: 31 Dec 2008
    5.4
    Medium

    CVE-2008-5787

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction with a show action.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5788

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Dec 2008
    5
    Medium

    CVE-2008-5794

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

    Published: 31 Dec 2008
    4.3
    Medium

    CVE-2008-5795

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5796

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5797

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5798

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the CMS Poll system (cms_poll) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 31 Dec 2008
    10
    Critical

    CVE-2008-5801

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5802

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5803

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5804

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5805

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5806

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.

    Published: 31 Dec 2008
    4.3
    Medium

    CVE-2008-5807

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) Testproject Names and (2) Testplan Names in planEdit.php, and possibly (3) Testcaseprefixes in projectview.tpl.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5800

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Wir ber uns [sic] (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 31 Dec 2008
    9.8
    Critical

    CVE-2008-5784

    Last Modified: 23 Apr 2026

    V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

    Published: 31 Dec 2008
    7.5
    High

    CVE-2008-5785

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Published: 31 Dec 2008
    9.3
    Critical

    CVE-2008-5764

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

    Published: 30 Dec 2008
    5
    Medium

    CVE-2008-5762

    Last Modified: 23 Apr 2026

    Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5768

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Dec 2008
    4.3
    Medium

    CVE-2008-5769

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer before 6.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) folder parameter to mailCompose.php or the (2) daytime parameter to calendarEdit.php. NOTE: some of these details are obtained from third party information.

    Published: 30 Dec 2008
    4.3
    Medium

    CVE-2008-5770

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5771

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5772

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.

    Published: 30 Dec 2008
    5
    Medium

    CVE-2008-5773

    Last Modified: 23 Apr 2026

    Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5774

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parameter to (c) detail.asp.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5767

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5778

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5779

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5781

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in right.php in Cant Find A Gaming CMS (CFAGCMS) 1.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the title parameter.

    Published: 30 Dec 2008