CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-3511

    Last Modified: 6 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Aug 2008
    7.5
    High

    CVE-2008-3513

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.

    Published: 7 Aug 2008
    2.1
    Low

    CVE-2008-1945

    Last Modified: 23 Apr 2026

    QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.

    Published: 7 Aug 2008
    6.4
    Medium

    CVE-2008-3659

    Last Modified: 23 Apr 2026

    Buffer overflow in the memnstr function in PHP 4.4.x before 4.4.9 and PHP 5.6 through 5.2.6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via the delimiter argument to the explode function. NOTE: the scope of this issue is limited since most applications would not use an attacker-controlled delimiter, but local attacks against safe_mode are feasible.

    Published: 7 Aug 2008
    7.5
    High

    CVE-2008-3658

    Last Modified: 23 Apr 2026

    Buffer overflow in the imageloadfont function in ext/gd/gd.c in PHP 4.4.x before 4.4.9 and PHP 5.2 before 5.2.6-r6 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

    Published: 7 Aug 2008
    5
    Medium

    CVE-2008-3492

    Last Modified: 23 Apr 2026

    America's Army (aka AA or Army Game Project) 2.8.3.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted UDP packet, probably involving a VoiceIndex value that is outside of the range specified by VOICE_MAX_CHATTERS.

    Published: 6 Aug 2008
    5
    Medium

    CVE-2008-3493

    Last Modified: 23 Apr 2026

    vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.

    Published: 6 Aug 2008
    7.8
    High

    CVE-2008-3494

    Last Modified: 23 Apr 2026

    8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text placed before the real Host header.

    Published: 6 Aug 2008
    4.3
    Medium

    CVE-2008-3500

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.

    Published: 6 Aug 2008
    4.3
    Medium

    CVE-2008-3501

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the WebAccess simple interface in Novell Groupwise 7.0.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Aug 2008
    4
    Medium

    CVE-2008-3502

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Best Practical Solutions RT 3.0.0 through 3.6.6 allows remote authenticated users to cause a denial of service (CPU or memory consumption) via unspecified vectors related to the Devel::StackTrace module for Perl.

    Published: 6 Aug 2008
    5
    Medium

    CVE-2008-3503

    Last Modified: 23 Apr 2026

    RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3506

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.

    Published: 6 Aug 2008
    6.8
    Medium

    CVE-2008-3497

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3498

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 6 Aug 2008
    10
    Critical

    CVE-2008-3499

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in "a page in the workarea folder" in Ektron CMS400.NET 7.00 through 7.04 and 7.50 through 7.52 has unknown impact and attack vectors.

    Published: 6 Aug 2008
    4.3
    Medium

    CVE-2008-3505

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3495

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3504

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies."

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3489

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.

    Published: 6 Aug 2008
    6.5
    Medium

    CVE-2008-3490

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3491

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3488

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via unknown vectors.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3487

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Aug 2008
    7.2
    High

    CVE-2008-3485

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed in the search path.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3486

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.

    Published: 6 Aug 2008
    6.9
    Medium

    CVE-2009-0318

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 6 Aug 2008
    6.9
    Medium

    CVE-2009-0317

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Python language bindings for Nautilus (nautilus-python) allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 6 Aug 2008
    6.9
    Medium

    CVE-2009-0315

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Python module in xchat allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 6 Aug 2008
    6.9
    Medium

    CVE-2009-0314

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 6 Aug 2008
    6.9
    Medium

    CVE-2008-5983

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

    Published: 6 Aug 2008
    6.9
    Medium

    CVE-2009-0316

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.

    Published: 6 Aug 2008
    5
    Medium

    CVE-2008-3660

    Last Modified: 23 Apr 2026

    PHP 4.4.x before 4.4.9, and 5.x through 5.2.6, when used as a FastCGI module, allows remote attackers to cause a denial of service (crash) via a request with multiple dots preceding the extension, as demonstrated using foo..php.

    Published: 6 Aug 2008
    7.5
    High

    CVE-2008-3484

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.

    Published: 5 Aug 2008
    4.3
    Medium

    CVE-2008-3483

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page.

    Published: 5 Aug 2008
    4.3
    Medium

    CVE-2008-3482

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Aug 2008
    4.6
    Medium

    CVE-2008-3356

    Last Modified: 23 Apr 2026

    verifydb in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and other Unix platforms sets the ownership or permissions of an iivdb.log file without verifying that it is the application's own log file, which allows local users to overwrite arbitrary files by creating a symlink with an iivdb.log filename.

    Published: 5 Aug 2008
    7.2
    High

    CVE-2008-3357

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges via a crafted shared library, related to a "pointer overwrite vulnerability."

    Published: 5 Aug 2008
    4.6
    Medium

    CVE-2008-3389

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the libbecompat library in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to gain privileges by setting a long value of an environment variable before running (1) verifydb, (2) iimerge, or (3) csreport.

    Published: 5 Aug 2008
    8.8
    High

    CVE-2008-3431

    Last Modified: 22 Apr 2026

    The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

    Published: 5 Aug 2008
    7.5
    High

    CVE-2008-3481

    Last Modified: 23 Apr 2026

    themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Published: 5 Aug 2008
    10
    Critical

    CVE-2008-5557

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not properly handled during Unicode conversion, related to the (1) mb_convert_encoding, (2) mb_check_encoding, (3) mb_convert_variables, and (4) mb_parse_str functions.

    Published: 5 Aug 2008
    4.3
    Medium

    CVE-2008-2939

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

    Published: 5 Aug 2008
    5
    Medium

    CVE-2008-3273

    Last Modified: 23 Apr 2026

    JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

    Published: 5 Aug 2008
    7.5
    High

    CVE-2008-4552

    Last Modified: 23 Apr 2026

    The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.

    Published: 5 Aug 2008
    4
    Medium

    CVE-2008-3451

    Last Modified: 23 Apr 2026

    PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.

    Published: 4 Aug 2008
    6.8
    Medium

    CVE-2008-3452

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.

    Published: 4 Aug 2008
    5
    Medium

    CVE-2008-3458

    Last Modified: 23 Apr 2026

    Vtiger CRM before 5.0.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read mail merge templates via a direct request to the wordtemplatedownload directory.

    Published: 4 Aug 2008
    6.4
    Medium

    CVE-2008-3456

    Last Modified: 23 Apr 2026

    phpMyAdmin before 2.11.8 does not sufficiently prevent its pages from using frames that point to pages in other domains, which makes it easier for remote attackers to conduct spoofing or phishing activities via a cross-site framing attack.

    Published: 4 Aug 2008
    2.6
    Low

    CVE-2008-3457

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in which the attacker must be able to modify config/config.inc.php.

    Published: 4 Aug 2008