CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-5230

    Last Modified: 23 Apr 2026

    The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi networks, has insufficient countermeasures against certain crafted and replayed packets, which makes it easier for remote attackers to decrypt packets from an access point (AP) to a client and spoof packets from an AP to a client, and conduct ARP poisoning attacks or other attacks, as demonstrated by tkiptun-ng.

    Published: 25 Nov 2008
    7.5
    High

    CVE-2008-5226

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a different vector than CVE-2007-5177.

    Published: 25 Nov 2008
    4.3
    Medium

    CVE-2008-5224

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.61 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Nov 2008
    4.3
    Medium

    CVE-2008-5225

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.

    Published: 25 Nov 2008
    7.5
    High

    CVE-2008-5223

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 25 Nov 2008
    7.5
    High

    CVE-2008-5222

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in Dvbbs 8.2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 25 Nov 2008
    5
    Medium

    CVE-2008-5218

    Last Modified: 23 Apr 2026

    ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.

    Published: 25 Nov 2008
    7.5
    High

    CVE-2008-5219

    Last Modified: 23 Apr 2026

    The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

    Published: 25 Nov 2008
    10
    Critical

    CVE-2008-5220

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in admin/tmp/.

    Published: 25 Nov 2008
    7.5
    High

    CVE-2008-5221

    Last Modified: 23 Apr 2026

    The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.

    Published: 25 Nov 2008
    4.3
    Medium

    CVE-2008-5278

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web script or HTML via the Host header (HTTP_HOST variable).

    Published: 25 Nov 2008
    7.5
    High

    CVE-2008-5208

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

    Published: 24 Nov 2008
    5
    Medium

    CVE-2008-5209

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 24 Nov 2008
    9.3
    Critical

    CVE-2008-5210

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in script/tick/, and (4) modules/dungeon/tick/allincludefortick.php, different vectors than CVE-2008-1776.

    Published: 24 Nov 2008
    2.6
    Low

    CVE-2008-5211

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attackers to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.

    Published: 24 Nov 2008
    7.5
    High

    CVE-2008-5212

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Published: 24 Nov 2008
    7.5
    High

    CVE-2008-5215

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.

    Published: 24 Nov 2008
    7.5
    High

    CVE-2008-5216

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 24 Nov 2008
    5.1
    Medium

    CVE-2008-5217

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.

    Published: 24 Nov 2008
    4.3
    Medium

    CVE-2008-5214

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.

    Published: 24 Nov 2008
    7.5
    High

    CVE-2008-5213

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.

    Published: 24 Nov 2008
    5.8
    Medium

    CVE-2008-7293

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

    Published: 24 Nov 2008
    7.8
    High

    CVE-2008-5714

    Last Modified: 23 Apr 2026

    Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

    Published: 23 Nov 2008
    7.2
    High

    CVE-2008-5396

    Last Modified: 23 Apr 2026

    Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to missing validation of the sync field associated with the ZT_SPANCONFIG ioctl.

    Published: 23 Nov 2008
    3.6
    Low

    CVE-2010-1626

    Last Modified: 11 Apr 2025

    MySQL before 5.1.46 allows local users to delete the data and index files of another user's MyISAM table via a symlink attack in conjunction with the DROP TABLE command, a different vulnerability than CVE-2008-4098 and CVE-2008-7247.

    Published: 22 Nov 2008
    5
    Medium

    CVE-2008-5285

    Last Modified: 23 Apr 2026

    Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.

    Published: 22 Nov 2008
    7.5
    High

    CVE-2008-5191

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.php and the (2) sp_id parameter to staticpages.php.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5192

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might overlap CVE-2008-2334, CVE-2008-1939, CVE-2007-2641, or CVE-2007-0920.

    Published: 21 Nov 2008
    4.3
    Medium

    CVE-2008-5193

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5194

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in checkavail.php in SoftVisions Software Online Booking Manager (obm) 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5195

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5196

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5190

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in eSHOP100 allows remote attackers to execute arbitrary SQL commands via the SUB parameter.

    Published: 21 Nov 2008
    4.3
    Medium

    CVE-2008-5202

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in OTManager CMS 24a allows remote attackers to inject arbitrary web script or HTML via the conteudo parameter.

    Published: 21 Nov 2008
    4.3
    Medium

    CVE-2008-5203

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in external_vote.php in PowerAward 1.1.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the l_vote_done parameter.

    Published: 21 Nov 2008
    6.8
    Medium

    CVE-2008-5207

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Jonascms 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the taal parameter to (1) backup.php and (2) gb_voegtoe.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5198

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL commands via the pow parameter.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5201

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5206

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/mod_mainmenu.php in MosXML 1 Alpha allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5197

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5199

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the gorumDir parameter.

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5200

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 21 Nov 2008
    6.8
    Medium

    CVE-2008-5204

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter to (1) agb.php, (2) angemeldet.php, (3) anmelden.php, (4) charts.php, (5) external_vote.php, (6) guestbook.php, (7) impressum.php, (8) index.php, (9) rss-reader.php, (10) statistic.php, (11) teilnehmer.php, (12) topsites.php, (13) votecode.php, (14) voting.php, and (15) winner.php.

    Published: 21 Nov 2008
    4.3
    Medium

    CVE-2008-5205

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action.

    Published: 21 Nov 2008
    5
    Medium

    CVE-2008-5185

    Last Modified: 23 Apr 2026

    The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequence containing an opening delimiter without a closing delimiter, as demonstrated using "<".

    Published: 21 Nov 2008
    7.5
    High

    CVE-2008-5186

    Last Modified: 23 Apr 2026

    The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi. Separate CVE identifiers would be created for web applications that integrate GeSHi in a way that allows control of the default language path

    Published: 21 Nov 2008
    10
    Critical

    CVE-2008-5177

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly execute arbitrary code on a Windows platform, related to ytwindtb.dll; via a long username field during authentication.

    Published: 20 Nov 2008
    9.3
    Critical

    CVE-2008-5178

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.

    Published: 20 Nov 2008
    5
    Medium

    CVE-2008-5179

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to cause a denial of service (crash) via a crafted Real-time Transport Control Protocol (RTCP) receiver report packet.

    Published: 20 Nov 2008
    5
    Medium

    CVE-2008-5181

    Last Modified: 23 Apr 2026

    Microsoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numbers of emoticons.

    Published: 20 Nov 2008