CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-4755

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Oct 2008
    4.3
    Medium

    CVE-2008-4756

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter.

    Published: 28 Oct 2008
    6.8
    Medium

    CVE-2008-4760

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Oct 2008
    9
    Critical

    CVE-2008-4762

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argument to the (1) rename and (2) realpath parameters.

    Published: 28 Oct 2008
    5
    Medium

    CVE-2008-4758

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter.

    Published: 28 Oct 2008
    5
    Medium

    CVE-2008-4759

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the id parameter.

    Published: 28 Oct 2008
    7.5
    High

    CVE-2008-4757

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php; and the (2) prev parameter to (d) prest_detail.php.

    Published: 28 Oct 2008
    4.3
    Medium

    CVE-2008-4761

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.

    Published: 28 Oct 2008
    2.1
    Low

    CVE-2008-4747

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the search feature in Sun Java System LDAP JDK before 4.20 allows context-dependent attackers to obtain sensitive information via unknown attack vectors related to the LDAP JDK library.

    Published: 27 Oct 2008
    9.3
    Critical

    CVE-2008-4750

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote attackers to execute arbitrary code via a long LogFile property.

    Published: 27 Oct 2008
    4.3
    Medium

    CVE-2008-4751

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597.

    Published: 27 Oct 2008
    7.5
    High

    CVE-2008-4752

    Last Modified: 23 Apr 2026

    TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.

    Published: 27 Oct 2008
    7.5
    High

    CVE-2008-4753

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter.

    Published: 27 Oct 2008
    5.8
    Medium

    CVE-2008-4754

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.

    Published: 27 Oct 2008
    9.3
    Critical

    CVE-2008-4749

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.

    Published: 27 Oct 2008
    7.6
    High

    CVE-2008-4748

    Last Modified: 23 Apr 2026

    Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the irc:// URI.

    Published: 27 Oct 2008
    5
    Medium

    CVE-2008-4741

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in FAR-PHP 1.00, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.

    Published: 27 Oct 2008
    4.3
    Medium

    CVE-2008-4742

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) password and (2) user_name parameters.

    Published: 27 Oct 2008
    7.5
    High

    CVE-2008-4743

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in QuidaScript FAQ Management Script allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 27 Oct 2008
    7.5
    High

    CVE-2008-4744

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 27 Oct 2008
    4.3
    Medium

    CVE-2008-4745

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in emailFriend.asp in Uniwin eCart Professional 2.0.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Oct 2008
    7.5
    High

    CVE-2008-4746

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Uniwin eCart Professional 2.0.17 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) search.asp and (2) cartUtil.asp.

    Published: 27 Oct 2008
    5.1
    Medium

    CVE-2008-4740

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the config[template] parameter.

    Published: 27 Oct 2008
    7.1
    High

    CVE-2008-6218

    Last Modified: 23 Apr 2026

    Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted PNG file.

    Published: 27 Oct 2008
    2.6
    Low

    CVE-2008-4775

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

    Published: 27 Oct 2008
    7.2
    High

    CVE-2008-4865

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario.

    Published: 27 Oct 2008
    7.5
    High

    CVE-2008-4734

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to perform unauthorized actions as administrators via a request that sets the wpcr_hidden_form_input parameter.

    Published: 24 Oct 2008
    7.5
    High

    CVE-2008-4736

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the showtopic parameter.

    Published: 24 Oct 2008
    4.3
    Medium

    CVE-2008-4737

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wholite.cgi in WhoDomLite 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the dom parameter.

    Published: 24 Oct 2008
    7.5
    High

    CVE-2008-4738

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Oct 2008
    7.5
    High

    CVE-2008-4732

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 24 Oct 2008
    8.5
    High

    CVE-2008-4735

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter.

    Published: 24 Oct 2008
    10
    Critical

    CVE-2008-4731

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in YaCy before 0.61 have unknown impact and attack vectors.

    Published: 24 Oct 2008
    6.8
    Medium

    CVE-2008-4739

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the navi parameter.

    Published: 24 Oct 2008
    4.3
    Medium

    CVE-2008-4730

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyID.php in phpMyID 0.9 allows remote attackers to inject arbitrary web script or HTML via the openid_trust_root parameter and an inconsistent openid_return_to parameter, which is not properly handled in an error message.

    Published: 24 Oct 2008
    4.3
    Medium

    CVE-2008-4733

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9) tagheaderlabel parameters.

    Published: 24 Oct 2008
    6.8
    Medium

    CVE-2008-4729

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.

    Published: 23 Oct 2008
    9
    Critical

    CVE-2008-4726

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a long string to the (1) open (aka SSH_FXP_OPEN), (2) unlink, (3) opendir, and other unspecified parameters.

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-4727

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant from a CSRF vulnerability, but there are insufficient details to be sure.

    Published: 23 Oct 2008
    9.3
    Critical

    CVE-2008-4728

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.

    Published: 23 Oct 2008
    9.8
    Critical

    CVE-2008-4250

    Last Modified: 20 May 2026

    The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

    Published: 23 Oct 2008
    10
    Critical

    CVE-2008-2469

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-3815

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.

    Published: 23 Oct 2008
    7.8
    High

    CVE-2008-3816

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2(4)9 and 7.2(4)10 allows remote attackers to cause a denial of service (device reload) via a crafted IPv6 packet.

    Published: 23 Oct 2008
    7.8
    High

    CVE-2008-3817

    Last Modified: 23 Apr 2026

    Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to the "initialization code for the hardware crypto accelerator."

    Published: 23 Oct 2008
    10
    Critical

    CVE-2008-3862

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data, related to "parsing CGI requests."

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-4696

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-4697

    Last Modified: 23 Apr 2026

    The Fast Forward feature in Opera before 9.61, when a page is located in a frame, executes a javascript: URL in the context of the outermost page instead of the page that contains this URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

    Published: 23 Oct 2008
    9.3
    Critical

    CVE-2008-4695

    Last Modified: 23 Apr 2026

    Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java applet and then launching this applet from the cache, leading to applet execution within the local-machine context.

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2007-4349

    Last Modified: 23 Apr 2026

    The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference.

    Published: 23 Oct 2008