CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-4694

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL.

    Published: 23 Oct 2008
    5.8
    Medium

    CVE-2008-4698

    Last Modified: 23 Apr 2026

    Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscriptions and read the contents of arbitrary feeds.

    Published: 23 Oct 2008
    9
    Critical

    CVE-2008-4722

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-4724

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome 0.2.149.30 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-4725

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4716

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4717

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4721

    Last Modified: 23 Apr 2026

    PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."

    Published: 23 Oct 2008
    9.3
    Critical

    CVE-2008-4720

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php.

    Published: 23 Oct 2008
    9.3
    Critical

    CVE-2008-4719

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter, a different vector than CVE-2008-4329.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4718

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the help_file parameter, a different vector than CVE-2006-2156.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4703

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.

    Published: 23 Oct 2008
    10
    Critical

    CVE-2008-4704

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4705

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4706

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.

    Published: 23 Oct 2008
    5
    Medium

    CVE-2008-4707

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a .. (dot dot) in the lien_2 parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4708

    Last Modified: 23 Apr 2026

    BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.

    Published: 23 Oct 2008
    6.8
    Medium

    CVE-2008-4711

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.

    Published: 23 Oct 2008
    6.8
    Medium

    CVE-2008-4712

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the plugin parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4713

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4714

    Last Modified: 23 Apr 2026

    Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4715

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

    Published: 23 Oct 2008
    7.5
    High

    CVE-2008-4709

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Oct 2008
    4.3
    Medium

    CVE-2008-4710

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Oct 2008
    7.2
    High

    CVE-2008-5188

    Last Modified: 23 Apr 2026

    The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.

    Published: 23 Oct 2008
    9.3
    Critical

    CVE-2008-4699

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4700

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_pass cookie parameter.

    Published: 22 Oct 2008
    7.5
    High

    CVE-2008-4702

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) user[language] and (2) user[template] parameters to (a) init.inc.php, and (b) the user[language] parameter to isadmin.inc.php.

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4701

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_user cookie parameter, a different vector than CVE-2008-4700. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Oct 2008
    9
    Critical

    CVE-2008-4687

    Last Modified: 23 Apr 2026

    manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

    Published: 22 Oct 2008
    5
    Medium

    CVE-2008-4688

    Last Modified: 23 Apr 2026

    core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issue data in the source anchor, which allows remote attackers to discover an issue's title and status via a request with a modified issue number.

    Published: 22 Oct 2008
    5
    Medium

    CVE-2008-4691

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) component in the server in IBM DB2 9.1 before FP6 allows attackers to cause a denial of service (segmentation violation and trap) via unknown vectors.

    Published: 22 Oct 2008
    5
    Medium

    CVE-2008-4693

    Last Modified: 23 Apr 2026

    The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace output, which allows attackers to obtain sensitive information by reading "PASSWORD-RELATED CONNECTION STRING KEYWORD VALUES."

    Published: 22 Oct 2008
    7.8
    High

    CVE-2008-4678

    Last Modified: 23 Apr 2026

    The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4679

    Last Modified: 23 Apr 2026

    The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.

    Published: 22 Oct 2008
    9.3
    Critical

    CVE-2008-4686

    Last Modified: 23 Apr 2026

    Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.

    Published: 22 Oct 2008
    10
    Critical

    CVE-2008-4692

    Last Modified: 23 Apr 2026

    The Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, preserves views and triggers without marking them inoperative or dropping them, which has unknown impact and attack vectors.

    Published: 22 Oct 2008
    7.5
    High

    CVE-2008-4665

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in PG Matchmaking allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) news_read.php and (2) gifts_show.php.

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4666

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter.

    Published: 22 Oct 2008
    7.5
    High

    CVE-2008-4667

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the rss parameter.

    Published: 22 Oct 2008
    9
    Critical

    CVE-2008-4668

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.

    Published: 22 Oct 2008
    4.3
    Medium

    CVE-2008-4672

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Oct 2008
    10
    Critical

    CVE-2008-4673

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the (1) path[docroot] and (2) component parameters.

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4674

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.

    Published: 22 Oct 2008
    7.5
    High

    CVE-2008-4675

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Published: 22 Oct 2008
    4.3
    Medium

    CVE-2008-4670

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Oct 2008
    4.3
    Medium

    CVE-2008-4671

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4676

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be the same issue as CVE-2008-3485, but the vendor advisory is too vague to be certain.

    Published: 22 Oct 2008
    4.3
    Medium

    CVE-2008-4669

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Oct 2008
    7.6
    High

    CVE-2008-3863

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.

    Published: 22 Oct 2008