CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2008-5322

    Last Modified: 23 Apr 2026

    Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.

    Published: 3 Dec 2008
    7.5
    High

    CVE-2008-5321

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.

    Published: 3 Dec 2008
    6.5
    Medium

    CVE-2008-5320

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.

    Published: 3 Dec 2008
    4.3
    Medium

    CVE-2008-5080

    Last Modified: 23 Apr 2026

    awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.

    Published: 3 Dec 2008
    5
    Medium

    CVE-2008-5319

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.

    Published: 3 Dec 2008
    5
    Medium

    CVE-2008-5318

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.

    Published: 3 Dec 2008
    6.9
    Medium

    CVE-2008-5313

    Last Modified: 23 Apr 2026

    mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5) bitdefender-wrapper, (6) kaspersky-wrapper, (7) clamav-wrapper, and (8) rav-wrapper scripts in /etc/MailScanner/wrapper/; the (9) Quarantine.pm, (10) TNEF.pm, (11) MessageBatch.pm, (12) WorkArea.pm, and (13) SA.pm scripts in /usr/share/MailScanner/MailScanner/; (14) /usr/sbin/MailScanner; and (15) scripts that load the /etc/MailScanner/mailscanner.conf.with.mcp configuration file.

    Published: 3 Dec 2008
    9.3
    Critical

    CVE-2008-5276

    Last Modified: 23 Apr 2026

    Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow.

    Published: 3 Dec 2008
    5
    Medium

    CVE-2008-3057

    Last Modified: 23 Apr 2026

    Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 3 Dec 2008
    6.9
    Medium

    CVE-2008-5312

    Last Modified: 23 Apr 2026

    mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in /etc/MailScanner/autoupdate/, a different vulnerability than CVE-2008-5140.

    Published: 3 Dec 2008
    7.8
    High

    CVE-2008-5315

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 3 Dec 2008
    7.5
    High

    CVE-2008-3058

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL commands via the FormValue_Email parameter (aka Email field) to index.php in (1) member/, (2) client/, or (3) admin/; or (4) the FormValue_SearchKeywords parameter to client/campaign_track.php.

    Published: 3 Dec 2008
    4
    Medium

    CVE-2008-3059

    Last Modified: 23 Apr 2026

    member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab.

    Published: 3 Dec 2008
    4.3
    Medium

    CVE-2009-1030

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

    Published: 3 Dec 2008
    7.5
    High

    CVE-2008-5347

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.

    Published: 3 Dec 2008
    4.3
    Medium

    CVE-2008-2379

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.

    Published: 3 Dec 2008
    7.1
    High

    CVE-2008-5349

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.

    Published: 3 Dec 2008
    7.5
    High

    CVE-2008-5308

    Last Modified: 23 Apr 2026

    The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.

    Published: 2 Dec 2008
    7.5
    High

    CVE-2008-5309

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.

    Published: 2 Dec 2008
    7.5
    High

    CVE-2008-5307

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Dec 2008
    7.5
    High

    CVE-2008-5310

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Dec 2008
    7.5
    High

    CVE-2008-5311

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Dec 2008
    7.5
    High

    CVE-2008-5306

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information.

    Published: 2 Dec 2008
    6.4
    Medium

    CVE-2008-5301

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5289

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Dec 2008
    4.3
    Medium

    CVE-2008-5290

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 1 Dec 2008
    6.9
    Medium

    CVE-2008-5299

    Last Modified: 23 Apr 2026

    chm2pdf 0.9 allows user-assisted local users to delete arbitrary files via a symlink attack on .chm files in the (1) /tmp/chm2pdf/work or (2) /tmp/chm2pdf/orig temporary directories.

    Published: 1 Dec 2008
    2.1
    Low

    CVE-2008-5298

    Last Modified: 23 Apr 2026

    chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5292

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5293

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5294

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5295

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.

    Published: 1 Dec 2008
    6.8
    Medium

    CVE-2008-5296

    Last Modified: 23 Apr 2026

    Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of these details are obtained from third party information.

    Published: 1 Dec 2008
    7.6
    High

    CVE-2008-5297

    Last Modified: 23 Apr 2026

    Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5291

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.

    Published: 1 Dec 2008
    6.8
    Medium

    CVE-2008-5288

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config_path parameter.

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5287

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 1 Dec 2008
    5
    Medium

    CVE-2008-6373

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Nagios before 3.0.6 has unspecified impact and remote attack vectors related to CGI programs, "adaptive external commands," and "writing newlines and submitting service comments."

    Published: 1 Dec 2008
    7.5
    High

    CVE-2008-5331

    Last Modified: 23 Apr 2026

    Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute-force attack.

    Published: 1 Dec 2008
    4.3
    Medium

    CVE-2008-5314

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.

    Published: 1 Dec 2008
    6.4
    Medium

    CVE-2008-5283

    Last Modified: 23 Apr 2026

    Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most recent version as of 20081128 is 1.2, and the File Upload Manager does not have a "delall" action.

    Published: 29 Nov 2008
    10
    Critical

    CVE-2008-5282

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.

    Published: 29 Nov 2008
    10
    Critical

    CVE-2008-5284

    Last Modified: 23 Apr 2026

    The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier, allows remote attackers to cause a denial of service (crash) via an HTTP Content-Length header with a negative value, which triggers a single byte overwrite of memory using a NULL terminator. NOTE: some of these details are obtained from third party information.

    Published: 29 Nov 2008
    10
    Critical

    CVE-2008-5281

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command.

    Published: 29 Nov 2008
    5
    Medium

    CVE-2008-5280

    Last Modified: 23 Apr 2026

    The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted requests without required parameters.

    Published: 29 Nov 2008
    10
    Critical

    CVE-2008-5279

    Last Modified: 23 Apr 2026

    The Local ZIM Server (zcs.exe) in Zilab Chat and Instant Messaging (ZIM) Server 2.1 and earlier allow remote attackers to execute arbitrary code via (1) heap-based buffer overflows involving multiple vectors including a long room name and a long source account, and (2) a stack-based buffer overflow with a long username in an information request. NOTE: some of these details are obtained from third party information.

    Published: 29 Nov 2008
    5
    Medium

    CVE-2008-5274

    Last Modified: 23 Apr 2026

    Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Nov 2008
    7.5
    High

    CVE-2008-5275

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, or delete arbitrary files via a .. (dot dot) in a filename within a (1) TAR or (2) ZIP archive. NOTE: this can be leveraged for code execution by creating a .php file.

    Published: 28 Nov 2008
    4.3
    Medium

    CVE-2008-5266

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.

    Published: 28 Nov 2008
    4.3
    Medium

    CVE-2008-5264

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the p parameter in a root action.

    Published: 28 Nov 2008