CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-3582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 10 Aug 2008
    10
    Critical

    CVE-2008-3576

    Last Modified: 23 Apr 2026

    Buffer overflow in the TruncateString function in src/gfx.cpp in OpenTTD before 0.6.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string. NOTE: some of these details are obtained from third party information.

    Published: 10 Aug 2008
    7.8
    High

    CVE-2008-3579

    Last Modified: 23 Apr 2026

    Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree. NOTE: this can be leveraged for remote exploitation of CVE-2008-3395. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Aug 2008
    4.3
    Medium

    CVE-2008-3581

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.

    Published: 10 Aug 2008
    6.8
    Medium

    CVE-2008-3561

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.

    Published: 10 Aug 2008
    5.1
    Medium

    CVE-2008-3562

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mods parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Aug 2008
    7.5
    High

    CVE-2008-3568

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote attackers to include and execute arbitrary local files via a full pathname in the Dirroot parameter, a different vulnerability than CVE-2006-4890.1.

    Published: 10 Aug 2008
    4.3
    Medium

    CVE-2008-3569

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php.

    Published: 10 Aug 2008
    7.8
    High

    CVE-2008-3571

    Last Modified: 23 Apr 2026

    The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.

    Published: 10 Aug 2008
    4.3
    Medium

    CVE-2008-3572

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pligg 9.9.5 allows remote attackers to inject arbitrary web script or HTML via the category parameter.

    Published: 10 Aug 2008
    4.3
    Medium

    CVE-2008-3565

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Aug 2008
    2.6
    Low

    CVE-2008-3574

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) lang_install22, (4) titelkop, (5) lang_kop1, (6) lang_kop2, (7) lang_modules, (8) lang_kop4, (9) lang_kop15, (10) lang_kop5, and (11) titelkop parameters to (b) data/inc/header.php; the pluck_version and titelkop parameters to (c) data/inc/header2.php; and the (14) lang_theme6 parameter to (d) data/inc/themeinstall.php.

    Published: 10 Aug 2008
    7.5
    High

    CVE-2008-3563

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the activate parameter to admin/plog-themes.php, related to theme_dir settings.

    Published: 10 Aug 2008
    4.3
    Medium

    CVE-2008-3566

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Aug 2008
    4.3
    Medium

    CVE-2008-3567

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.

    Published: 10 Aug 2008
    7.5
    High

    CVE-2008-3575

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[gsLanguage] parameter, a different vector than CVE-2006-4477 and CVE-2004-0132.

    Published: 10 Aug 2008
    7.5
    High

    CVE-2008-3564

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p, (2) cat, and (3) archive parameters. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 10 Aug 2008
    7.5
    High

    CVE-2008-3570

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter.

    Published: 10 Aug 2008
    5
    Medium

    CVE-2008-3573

    Last Modified: 23 Apr 2026

    The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.

    Published: 10 Aug 2008
    4
    Medium

    CVE-2008-3963

    Last Modified: 23 Apr 2026

    MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.

    Published: 10 Aug 2008
    4
    Medium

    CVE-2008-6098

    Last Modified: 23 Apr 2026

    Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, 2.20 before 2.20.7, and other versions after 2.17.4 allows remote authenticated users to bypass moderation to approve and disapprove quips via a direct request to quips.cgi with the action parameter set to "approve."

    Published: 9 Aug 2008
    6.4
    Medium

    CVE-2008-3337

    Last Modified: 23 Apr 2026

    PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.

    Published: 8 Aug 2008
    10
    Critical

    CVE-2008-3552

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 11-15." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 8 Aug 2008
    7.5
    High

    CVE-2008-3554

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.

    Published: 8 Aug 2008
    9.3
    Critical

    CVE-2008-3558

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.

    Published: 8 Aug 2008
    4.3
    Medium

    CVE-2008-3560

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 8 Aug 2008
    7.5
    High

    CVE-2008-3557

    Last Modified: 23 Apr 2026

    Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies.

    Published: 8 Aug 2008
    7.6
    High

    CVE-2008-2377

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the _gnutls_handshake_hash_buffers_clear function in lib/gnutls_handshake.c in libgnutls in GnuTLS 2.3.5 through 2.4.0 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via TLS transmission of data that is improperly used when the peer calls gnutls_handshake within a normal session, leading to attempted access to a deallocated libgcrypt handle.

    Published: 8 Aug 2008
    6.8
    Medium

    CVE-2008-3555

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences.

    Published: 8 Aug 2008
    5
    Medium

    CVE-2008-3550

    Last Modified: 23 Apr 2026

    The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows remote attackers to obtain potentially sensitive information (page source code) via a combination of ?script? and ?/script? sequences in the id field, possibly related to a cross-site scripting (XSS) vulnerability.

    Published: 8 Aug 2008
    10
    Critical

    CVE-2008-3551

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 8 Aug 2008
    7.5
    High

    CVE-2008-3556

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action. NOTE: vector 1 might be the same as CVE-2008-2522.

    Published: 8 Aug 2008
    4.3
    Medium

    CVE-2008-3559

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Aug 2008
    7.8
    High

    CVE-2008-1664

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 8 Aug 2008
    10
    Critical

    CVE-2008-3553

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 3-10." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 8 Aug 2008
    9.3
    Critical

    CVE-2008-0964

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.

    Published: 8 Aug 2008
    9.3
    Critical

    CVE-2008-0965

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.

    Published: 8 Aug 2008
    7.8
    High

    CVE-2008-3656

    Last Modified: 23 Apr 2026

    Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.

    Published: 8 Aug 2008
    4.7
    Medium

    CVE-2008-3524

    Last Modified: 23 Apr 2026

    rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run.

    Published: 8 Aug 2008
    7.5
    High

    CVE-2008-3655

    Last Modified: 23 Apr 2026

    Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.

    Published: 8 Aug 2008
    7.5
    High

    CVE-2008-3657

    Last Modified: 23 Apr 2026

    The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.

    Published: 8 Aug 2008
    5.8
    Medium

    CVE-2008-3905

    Last Modified: 23 Apr 2026

    resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

    Published: 8 Aug 2008
    7.5
    High

    CVE-2008-3546

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the (1) diff_addremove and (2) diff_change functions in GIT before 1.5.6.4 might allow local users to execute arbitrary code via a PATH whose length is larger than the system's PATH_MAX when running GIT utilities such as git-diff or git-grep.

    Published: 7 Aug 2008
    4.9
    Medium

    CVE-2008-3548

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Sun Netra T5220 Server with firmware 7.1.3 allows local users to cause a denial of service (panic) via unknown vectors.

    Published: 7 Aug 2008
    4.7
    Medium

    CVE-2008-3549

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris before snv_90 allows local users to cause a denial of service (system hang or panic) via unknown vectors.

    Published: 7 Aug 2008
    7.5
    High

    CVE-2008-3507

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

    Published: 7 Aug 2008
    5
    Medium

    CVE-2008-3508

    Last Modified: 23 Apr 2026

    LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.

    Published: 7 Aug 2008
    7.5
    High

    CVE-2008-3509

    Last Modified: 23 Apr 2026

    LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

    Published: 7 Aug 2008
    4.3
    Medium

    CVE-2008-3510

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.

    Published: 7 Aug 2008
    7.5
    High

    CVE-2008-3512

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.

    Published: 7 Aug 2008