CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-5636

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5637

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter.

    Published: 17 Dec 2008
    5
    Medium

    CVE-2008-5642

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a cms_language cookie.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5632

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5638

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Active Price Comparison 4 allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter to reviews.aspx or the (2) linkid parameter to links.asp.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5640

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Published: 17 Dec 2008
    4.3
    Medium

    CVE-2008-5639

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via a .. (dot dot) in the m parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5627

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter (aka Email field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5631

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5633

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5641

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 17 Dec 2008
    6
    Medium

    CVE-2008-5621

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remote attackers to perform unauthorized actions as the administrator via a link or IMG tag to tbl_structure.php with a modified table parameter. NOTE: other unspecified pages are also reachable, but they have the same root cause. NOTE: this can be leveraged to conduct SQL injection attacks and execute arbitrary code.

    Published: 17 Dec 2008
    Unknown

    CVE-2008-5622

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5621. Reason: This candidate is a duplicate of CVE-2008-5621. Notes: All CVE users should reference CVE-2008-5621 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Dec 2008
    8.5
    High

    CVE-2008-5617

    Last Modified: 23 Apr 2026

    The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.

    Published: 17 Dec 2008
    9.3
    Critical

    CVE-2008-4217

    Last Modified: 23 Apr 2026

    Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-based buffer overflow.

    Published: 17 Dec 2008
    7.2
    High

    CVE-2008-4218

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386_get_ldt.

    Published: 17 Dec 2008
    4.9
    Medium

    CVE-2008-4219

    Last Modified: 23 Apr 2026

    The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite loop and system halt) by running an application that is dynamically linked to libraries on an NFS server, related to occurrence of an exception in this application.

    Published: 17 Dec 2008
    10
    Critical

    CVE-2008-4220

    Last Modified: 23 Apr 2026

    Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. NOTE: this may be related to the WLB-2008080064 advisory published by SecurityReason on 20080822; however, as of 20081216, there are insufficient details to be sure.

    Published: 17 Dec 2008
    10
    Critical

    CVE-2008-4221

    Last Modified: 23 Apr 2026

    The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted date string, related to improper memory allocation.

    Published: 17 Dec 2008
    9.3
    Critical

    CVE-2008-4234

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a "potentially unsafe" warning message.

    Published: 17 Dec 2008
    7.1
    High

    CVE-2008-4236

    Last Modified: 23 Apr 2026

    Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.

    Published: 17 Dec 2008
    10
    Critical

    CVE-2008-4237

    Last Modified: 23 Apr 2026

    Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated by the screen saver lock setting.

    Published: 17 Dec 2008
    7.1
    High

    CVE-2008-4222

    Last Modified: 23 Apr 2026

    natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.

    Published: 17 Dec 2008
    10
    Critical

    CVE-2008-4223

    Last Modified: 23 Apr 2026

    Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5609

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Commerce extension 0.9.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Dec 2008
    7.1
    High

    CVE-2008-4224

    Last Modified: 23 Apr 2026

    UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.

    Published: 17 Dec 2008
    10
    Critical

    CVE-2008-5616

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file.

    Published: 17 Dec 2008
    9.3
    Critical

    CVE-2008-5499

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.

    Published: 17 Dec 2008
    7.2
    High

    CVE-2008-5086

    Last Modified: 23 Apr 2026

    Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.

    Published: 17 Dec 2008
    6.8
    Medium

    CVE-2008-5586

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 16 Dec 2008
    4.3
    Medium

    CVE-2008-5591

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained from third party information.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5592

    Last Modified: 23 Apr 2026

    Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5593

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5594

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page and (2) admin parameters.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5595

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5598

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary directories via a .. (dot dot) in the group parameter.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5599

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL commands via the password parameter (aka passwd field) in a login action. NOTE: some of these details are obtained from third party information.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5600

    Last Modified: 23 Apr 2026

    Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for teamworx.mdb.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5603

    Last Modified: 23 Apr 2026

    ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for news.mdb.

    Published: 16 Dec 2008
    6.8
    Medium

    CVE-2008-5604

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5605

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1) ItemID parameter to classifieds.asp and the (2) ID parameter to Events.asp.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5606

    Last Modified: 23 Apr 2026

    Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5588

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL commands via the siteID parameter.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5602

    Last Modified: 23 Apr 2026

    Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for natterchat112.mdb.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5585

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5590

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remote attackers to execute arbitrary SQL commands via the forum_topic_id parameter.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5597

    Last Modified: 23 Apr 2026

    Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for db/cforum.mdb.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5608

    Last Modified: 23 Apr 2026

    ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for auto.mdb.

    Published: 16 Dec 2008
    4.3
    Medium

    CVE-2008-5587

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5589

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL commands via the (1) txtusername parameter (aka username field) or the (2) txtpassword parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Published: 16 Dec 2008