CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-5089

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the DDActiveReportsViewer2.ARViewer2 ActiveX control (arview2.ocx) in Data Dynamics ActiveReports 2.5.0.1314 allow remote attackers to overwrite arbitrary files via a call to the (1) Pages.Save, (2) PrintReport, or (3) Canvas.Save method.

    Published: 14 Nov 2008
    10
    Critical

    CVE-2008-5090

    Last Modified: 23 Apr 2026

    Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.

    Published: 14 Nov 2008
    10
    Critical

    CVE-2008-5091

    Last Modified: 23 Apr 2026

    Buffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (application crash) via vectors involving an "invalid extensibleMatch filter."

    Published: 14 Nov 2008
    10
    Critical

    CVE-2008-5092

    Last Modified: 23 Apr 2026

    Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header.

    Published: 14 Nov 2008
    4.3
    Medium

    CVE-2008-5093

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 14 Nov 2008
    10
    Critical

    CVE-2008-5094

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.

    Published: 14 Nov 2008
    5
    Medium

    CVE-2008-5096

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TYPO3 File List (file_list) extension 0.2.1 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5088

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5097

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MyFWB 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5087

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in TYPO3 Another Backend Login (wrg_anotherbelogin) extension before 0.0.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Nov 2008
    4.3
    Medium

    CVE-2008-5095

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5069

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Nov 2008
    9
    Critical

    CVE-2008-5071

    Last Modified: 23 Apr 2026

    Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP code via the proj_id parameter.

    Published: 14 Nov 2008
    4.3
    Medium

    CVE-2008-5072

    Last Modified: 23 Apr 2026

    vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file.

    Published: 14 Nov 2008
    6.8
    Medium

    CVE-2008-5075

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to (g) browser.php.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5070

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5074

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Published: 14 Nov 2008
    9.3
    Critical

    CVE-2008-5073

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstall method.

    Published: 14 Nov 2008
    7.5
    High

    CVE-2008-5187

    Last Modified: 23 Apr 2026

    The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.

    Published: 14 Nov 2008
    4.3
    Medium

    CVE-2008-5067

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5064

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 Nov 2008
    4.3
    Medium

    CVE-2008-5068

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter to index.php and the (2) searchtext parameter to search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5065

    Last Modified: 23 Apr 2026

    TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.

    Published: 13 Nov 2008
    10
    Critical

    CVE-2008-5066

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5055

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5058

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in siteadmin/loginsucess.php in Pre Simple CMS allows remote attackers to execute arbitrary SQL commands via the user parameter, as reachable from siteadmin/adminlogin.php. NOTE: some of these details are obtained from third party information.

    Published: 13 Nov 2008
    4.3
    Medium

    CVE-2008-5059

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ModernBill 4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript event in the new_language parameter in a login action.

    Published: 13 Nov 2008
    4.3
    Medium

    CVE-2008-5061

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 13 Nov 2008
    5
    Medium

    CVE-2008-5062

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5057

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Nov 2008
    10
    Critical

    CVE-2008-5053

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5054

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_login.php and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.

    Published: 13 Nov 2008
    10
    Critical

    CVE-2008-5060

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php in include/scripts/; (4) include/misc/mod_2checkout/2checkout_return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054.

    Published: 13 Nov 2008
    4.3
    Medium

    CVE-2008-5056

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.

    Published: 13 Nov 2008
    10
    Critical

    CVE-2008-5063

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the Tipo parameter.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5046

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL commands via the manufacturers_id parameter.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5047

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 13 Nov 2008
    7.2
    High

    CVE-2008-5048

    Last Modified: 23 Apr 2026

    Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL.

    Published: 13 Nov 2008
    7.2
    High

    CVE-2008-5049

    Last Modified: 23 Apr 2026

    Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other versions including 3.3.3, allows local users to gain privileges via long inputs to the (1) 0x002224A4, (2) 0x002224C0, and (3) 0x002224CC IOCTL.

    Published: 13 Nov 2008
    7.5
    High

    CVE-2008-5051

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PostID parameter to index.php.

    Published: 13 Nov 2008
    9.3
    Critical

    CVE-2008-5050

    Last Modified: 23 Apr 2026

    Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow.

    Published: 13 Nov 2008
    10
    Critical

    CVE-2008-5045

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to cause a denial of service (crash) via a 200 server response that is exactly 1024 characters long.

    Published: 13 Nov 2008
    3.5
    Low

    CVE-2008-5043

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web-based interface in IBM Metrica Service Assurance Framework allow remote authenticated users to inject arbitrary web script or HTML via (1) the elementid parameter in a generatedreportresults action to the ReportTree program, (2) the jnlpname parameter to the Launch program, or (3) the :tasklabel parameter to the ReportRequest program, related to the name of a report.

    Published: 12 Nov 2008
    4.3
    Medium

    CVE-2008-4029

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka "MSXML DTD Cross-Domain Scripting Vulnerability."

    Published: 12 Nov 2008
    4.3
    Medium

    CVE-2008-4033

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

    Published: 12 Nov 2008
    9.3
    Critical

    CVE-2008-4037

    Last Modified: 23 Apr 2026

    Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.

    Published: 12 Nov 2008
    4
    Medium

    CVE-2008-5044

    Last Modified: 23 Apr 2026

    Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5041

    Last Modified: 23 Apr 2026

    Sweex RO002 Router with firmware Ts03-072 has "rdc123" as its default password for the "rdc123" account, which makes it easier for remote attackers to obtain access. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5042

    Last Modified: 23 Apr 2026

    Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5037

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 12 Nov 2008