CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-3201

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Pagefusion 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) acct_fname and (2) acct_lname parameters in an edit action, and the (3) PID, (4) PGID, and (5) rez parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Jul 2008
    7.5
    High

    CVE-2008-3204

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.

    Published: 17 Jul 2008
    5
    Medium

    CVE-2008-3205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.

    Published: 17 Jul 2008
    7.5
    High

    CVE-2008-3203

    Last Modified: 23 Apr 2026

    js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.

    Published: 17 Jul 2008
    9
    Critical

    CVE-2008-1665

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in HP Select Identity (HPSI) Active Directory Bidirectional LDAP Connector 2.20, 2.20.001, 2.20.002, and 2.30 allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 17 Jul 2008
    4.3
    Medium

    CVE-2008-3202

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the current_url parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Jul 2008
    3.7
    Low

    CVE-2008-3294

    Last Modified: 23 Apr 2026

    src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

    Published: 17 Jul 2008
    7.5
    High

    CVE-2008-3189

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Jul 2008
    6.8
    Medium

    CVE-2008-3192

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in jSite 1.0 OE allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Published: 16 Jul 2008
    3.5
    Low

    CVE-2008-3197

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in phpMyAdmin before 2.11.7.1 allows remote attackers to perform unauthorized actions via a link or IMG tag to (1) the db parameter in the "Creating a Database" functionality (db_create.php), and (2) the convcharset and collation_connection parameters related to an unspecified program that modifies the connection character set.

    Published: 16 Jul 2008
    6.8
    Medium

    CVE-2008-3190

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 16 Jul 2008
    6.8
    Medium

    CVE-2008-3191

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.

    Published: 16 Jul 2008
    7.5
    High

    CVE-2008-3193

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page parameter to the default URI.

    Published: 16 Jul 2008
    6.8
    Medium

    CVE-2008-3194

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) langpref, (2) file, (3) blogpost, or (4) cat parameter.

    Published: 16 Jul 2008
    4.6
    Medium

    CVE-2008-3791

    Last Modified: 23 Apr 2026

    src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.

    Published: 16 Jul 2008
    5
    Medium

    CVE-2008-2582

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    1.5
    Low

    CVE-2008-2587

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and local attack vectors.

    Published: 15 Jul 2008
    3.5
    Low

    CVE-2008-2590

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enterprise Manager 10.1.0.6 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2596

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Mobile Application Server component in Oracle E-Business Suite 12.0.3 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-2597

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TimesTen Client/Server component in Oracle Times Ten In-Memory Database 7.0.3.0.0 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2598 and CVE-2008-2599.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-2598

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TimesTen Client/Server component in Oracle Times Ten In-Memory Database 7.0.3.0.0 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2597 and CVE-2008-2599.

    Published: 15 Jul 2008
    4.6
    Medium

    CVE-2008-2602

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to the IMP_FULL_DATABASE role.

    Published: 15 Jul 2008
    3.5
    Low

    CVE-2008-2603

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Resource Manager component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6, and Database Control in Enterprise Manager, has unknown impact and remote authenticated attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is a cross-site scripting (XSS) issue that allows remote attackers to inject arbitrary web script or HTML via the REFRESHCHOICE parameter in multiple web pages.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2604

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2605.

    Published: 15 Jul 2008
    4
    Medium

    CVE-2008-2605

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2604.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2606

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2586.

    Published: 15 Jul 2008
    5.5
    Medium

    CVE-2008-2601

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    4
    Medium

    CVE-2008-2608

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote authenticated attack vectors related to SYS.KUPF$FILE_INT.

    Published: 15 Jul 2008
    6.4
    Medium

    CVE-2008-2609

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2610

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    4
    Medium

    CVE-2008-2611

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-2612

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Hyperion BI Plus component in Oracle Application Server 8.3.2.4, 8.5.0.3, 9.2.0.3, 9.2.1.0, and 9.3.1.0 has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2618

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2616

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2617

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2622

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, and CVE-2008-2621.

    Published: 15 Jul 2008
    4.4
    Medium

    CVE-2008-2576

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2, 9.1, 9.0, and 8.1 SP6 has unknown impact and local attack vectors.

    Published: 15 Jul 2008
    5.1
    Medium

    CVE-2008-2581

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors related to UDDI Explorer.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2585

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-2593

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2594.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2613

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path issue that allows local users to gain privileges via a malicious (1) libclntsh.so or (2) libnnz10.so library.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2620

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2621, and CVE-2008-2622.

    Published: 15 Jul 2008
    4.6
    Medium

    CVE-2008-2577

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2 MP1 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-2579

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    5
    Medium

    CVE-2008-2580

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, and 9.0 has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-2583

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the sample Discussion Forum Portlet for the Oracle Portal component in Oracle Application Server, as available from OTN before 20080715, has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    4
    Medium

    CVE-2008-2586

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2606.

    Published: 15 Jul 2008
    6.4
    Medium

    CVE-2008-2589

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3, 10.1.2.2, and 10.1.4.1 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a SQL injection vulnerability in the WWV_RENDER_REPORT package that allows remote attackers to execute arbitrary SQL (PL/SQL) commands via the second argument to the SHOW procedure.

    Published: 15 Jul 2008
    5.5
    Medium

    CVE-2008-2592

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_DEFER_SYS. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is a SQL injection vulnerability in the DELETE_TRAN procedure.

    Published: 15 Jul 2008
    6.4
    Medium

    CVE-2008-2594

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2593.

    Published: 15 Jul 2008