CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-5761

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter to the default URI; (2) the foto parameter to photo.php in the 05_Foto module; or (3) the name parameter in an insertrecord action to index.php in the 08_Files module, as demonstrated by injection within a SRC attribute of an IFRAME element.

    Published: 30 Dec 2008
    5
    Medium

    CVE-2008-5765

    Last Modified: 23 Apr 2026

    WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for data/usr.txt.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5766

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5775

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5763

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5776

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to admin.php and the (2) get parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5777

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 30 Dec 2008
    5
    Medium

    CVE-2008-5780

    Last Modified: 23 Apr 2026

    Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing passwords via a direct request for blog.mdb.

    Published: 30 Dec 2008
    Unknown

    CVE-2008-4270

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5416. Reason: This candidate is a duplicate of CVE-2008-5416. Notes: All CVE users should reference CVE-2008-5416 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Dec 2008
    6.8
    Medium

    CVE-2008-5758

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in PHParanoid before 0.5 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors related to private messages.

    Published: 30 Dec 2008
    4.3
    Medium

    CVE-2008-5760

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

    Published: 30 Dec 2008
    4.3
    Medium

    CVE-2008-5759

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web script or HTML via the name parameter in an updaterecord action to index.php in the 08_Files module. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Dec 2008
    3.5
    Low

    CVE-2008-5757

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in textarea/index.php in Textpattern (aka Txp CMS) 4.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Body parameter in an article action. NOTE: some of these details are obtained from third party information.

    Published: 30 Dec 2008
    7.5
    High

    CVE-2008-5751

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.

    Published: 30 Dec 2008
    4.3
    Medium

    CVE-2008-5752

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information.

    Published: 30 Dec 2008
    9.3
    Critical

    CVE-2008-5755

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP file containing a long URL, possibly a related issue to CVE-2006-2494.

    Published: 30 Dec 2008
    9.3
    Critical

    CVE-2008-5756

    Last Modified: 23 Apr 2026

    Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service and possibly execute arbitrary code via a long mapping reference in a Color Mapping (.cmap) file.

    Published: 30 Dec 2008
    9.3
    Critical

    CVE-2008-5754

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753.

    Published: 30 Dec 2008
    9.3
    Critical

    CVE-2008-5753

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry with a long host name, which appears as a host parameter within the quick-connect bar.

    Published: 30 Dec 2008
    6.8
    Medium

    CVE-2008-5824

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WAV file.

    Published: 30 Dec 2008
    9.8
    Critical

    CVE-2004-2761

    Last Modified: 28 May 2026

    The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.

    Published: 30 Dec 2008
    8.1
    High

    CVE-2008-5748

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

    Published: 29 Dec 2008
    6.8
    Medium

    CVE-2008-5750

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.

    Published: 29 Dec 2008
    4.3
    Medium

    CVE-2008-5745

    Last Modified: 23 Apr 2026

    Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.

    Published: 29 Dec 2008
    6.9
    Medium

    CVE-2008-5746

    Last Modified: 23 Apr 2026

    Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 allows local users to overwrite arbitrary files and gain privileges via a symlink attack on temporary files.

    Published: 29 Dec 2008
    5
    Medium

    CVE-2008-5747

    Last Modified: 23 Apr 2026

    F-Prot 4.6.8 for GNU/Linux allows remote attackers to bypass anti-virus protection via a crafted ELF program with a "corrupted" header that still allows the program to be executed. NOTE: due to an error in the initial disclosure, F-secure was incorrectly stated as the vendor.

    Published: 29 Dec 2008
    6.8
    Medium

    CVE-2008-5749

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission.

    Published: 29 Dec 2008
    10
    Critical

    CVE-2008-6393

    Last Modified: 23 Apr 2026

    PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

    Published: 29 Dec 2008
    9.3
    Critical

    CVE-2008-2383

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issue to CVE-2003-0063 and CVE-2003-0071.

    Published: 29 Dec 2008
    6.9
    Medium

    CVE-2008-5743

    Last Modified: 23 Apr 2026

    pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup files with a predictable name, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 26 Dec 2008
    4
    Medium

    CVE-2008-5742

    Last Modified: 23 Apr 2026

    Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.

    Published: 26 Dec 2008
    7.5
    High

    CVE-2008-5738

    Last Modified: 23 Apr 2026

    Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2 cookie to 1. NOTE: some of these details are obtained from third party information.

    Published: 26 Dec 2008
    7.5
    High

    CVE-2008-5739

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.

    Published: 26 Dec 2008
    7.2
    High

    CVE-2008-5736

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown attack vectors related to function pointers that are "not properly initialized" for (1) netgraph sockets and (2) bluetooth sockets.

    Published: 26 Dec 2008
    9.3
    Critical

    CVE-2008-5735

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code via a large PlaylistSkin value in a skin file.

    Published: 26 Dec 2008
    7.5
    High

    CVE-2008-5737

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 26 Dec 2008
    9.3
    Critical

    CVE-2008-5718

    Last Modified: 23 Apr 2026

    The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as demonstrated using a crafted Title.

    Published: 26 Dec 2008
    7.2
    High

    CVE-2008-5725

    Last Modified: 23 Apr 2026

    The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local users to gain privileges via certain IRP parameters in an IOCTL request to \Device\Powerstrip1 that overwrites portions of memory.

    Published: 26 Dec 2008
    6.8
    Medium

    CVE-2008-5727

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the query string.

    Published: 26 Dec 2008
    7.5
    High

    CVE-2008-5730

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vectors involving (1) a %0a sequence in a cookie and (2) the add.php file.

    Published: 26 Dec 2008
    7.5
    High

    CVE-2008-5732

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.

    Published: 26 Dec 2008
    7.5
    High

    CVE-2008-5733

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 26 Dec 2008
    4.3
    Medium

    CVE-2008-5734

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.

    Published: 26 Dec 2008
    4.3
    Medium

    CVE-2008-5729

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) form and (2) control parameters to FCKeditor/neditor.php, and the (3) path parameter to admin/siteinfo/iframe.inc.php.

    Published: 26 Dec 2008
    4.3
    Medium

    CVE-2008-5717

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Hitachi JP1/Integrated Management - Service Support 08-10 through 08-10-05, 08-11 through 08-11-03, and 08-50 through 08-50-03 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2008
    4.3
    Medium

    CVE-2008-5720

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the default error page for the org.seasar.mayaa.impl.engine.PageNotFoundException exception and possibly other exceptions.

    Published: 26 Dec 2008
    5.1
    Medium

    CVE-2008-5728

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the system parameter in modules/netshop/post.php; and the INCLUDE_FOLDER parameter in (2) auth.inc.php, (3) banner.inc.php, (4) blog.inc.php, and (5) forum.inc.php in modules/.

    Published: 26 Dec 2008
    4.3
    Medium

    CVE-2008-5719

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Hitachi Groupmax Web Workflow SDK Set for Active Server Pages before 06-52-/C and Hitachi Groupmax Workflow - Development Kit for Active Server Pages before 06-52-/A allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Dec 2008
    5
    Medium

    CVE-2008-5721

    Last Modified: 23 Apr 2026

    SapporoWorks BlackJumboDog (BJD) before 4.2.3 allows remote attackers to bypass authentication and obtain sensitive information via unspecified vectors.

    Published: 26 Dec 2008
    10
    Critical

    CVE-2008-5722

    Last Modified: 23 Apr 2026

    Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file.

    Published: 26 Dec 2008