CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-3381

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jul 2008
    7.5
    High

    CVE-2008-3154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 11 Jul 2008
    9.3
    Critical

    CVE-2008-3155

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method.

    Published: 11 Jul 2008
    5
    Medium

    CVE-2008-3157

    Last Modified: 23 Apr 2026

    Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows attackers to cause a denial of service (resource consumption) via a large number of sessions.

    Published: 11 Jul 2008
    7.5
    High

    CVE-2008-3151

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_dvd action.

    Published: 11 Jul 2008
    6.9
    Medium

    CVE-2008-3158

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

    Published: 11 Jul 2008
    7.5
    High

    CVE-2008-3152

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter.

    Published: 11 Jul 2008
    7.5
    High

    CVE-2008-3153

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

    Published: 11 Jul 2008
    9.3
    Critical

    CVE-2008-3156

    Last Modified: 23 Apr 2026

    The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.

    Published: 11 Jul 2008
    4.7
    Medium

    CVE-2008-3147

    Last Modified: 23 Apr 2026

    WeFi 3.2.1.4.1, when diagnostic mode is enabled, stores (1) WEP, (2) WPA, and (3) WPA2 access-point keys in (a) ClientWeFiLog.dat, (b) ClientWeFiLog.bak, and possibly (c) a certain .inf file under %PROGRAMFILES%\WeFi\Users\, and uses cleartext for the ClientWeFiLog files, which allows local users to obtain sensitive information by reading these files.

    Published: 11 Jul 2008
    6.8
    Medium

    CVE-2008-3148

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file that contains a long string.

    Published: 11 Jul 2008
    10
    Critical

    CVE-2008-3150

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access restrictions that were implemented in sess.php.

    Published: 11 Jul 2008
    7.8
    High

    CVE-2008-3149

    Last Modified: 23 Apr 2026

    The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstalled OID branch in HOST-RESOURCES-MIB.

    Published: 11 Jul 2008
    7.5
    High

    CVE-2008-3129

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form.

    Published: 10 Jul 2008
    6.8
    Medium

    CVE-2008-3131

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3132

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.

    Published: 10 Jul 2008
    6.8
    Medium

    CVE-2008-3133

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3136

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 10 Jul 2008
    6.8
    Medium

    CVE-2008-3127

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.

    Published: 10 Jul 2008
    7.8
    High

    CVE-2008-3135

    Last Modified: 23 Apr 2026

    Soldner Secret Wars 33724 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a large numeric value in a 0x80 data block.

    Published: 10 Jul 2008
    5
    Medium

    CVE-2008-3128

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.

    Published: 10 Jul 2008
    4.3
    Medium

    CVE-2008-3130

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in OpenCart 0.7.7 allow remote attackers to inject arbitrary web script or HTML via the (1) firstname and (2) search parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jul 2008
    4.3
    Medium

    CVE-2008-3121

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Jul 2008
    6.5
    Medium

    CVE-2008-3122

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to execute arbitrary SQL commands via the unspecified vectors.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3123

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3124

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3125

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 10 Jul 2008
    Unknown

    CVE-2008-3120

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3363. Reason: This candidate is a duplicate of CVE-2008-3363. Notes: All CVE users should reference CVE-2008-3363 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3119

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 10 Jul 2008
    6.5
    Medium

    CVE-2008-3126

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the ServerView web interface (SnmpGetMibValues.exe) in Fujitsu Siemens Computers ServerView 04.60.07 and earlier allow remote authenticated users to execute arbitrary code via a crafted URL.

    Published: 10 Jul 2008
    10
    Critical

    CVE-2008-3116

    Last Modified: 23 Apr 2026

    Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3118

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.

    Published: 10 Jul 2008
    6.5
    Medium

    CVE-2008-3117

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/.

    Published: 10 Jul 2008
    5
    Medium

    CVE-2008-3145

    Last Modified: 23 Apr 2026

    The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packets with non-sequential fragmentation offset values, which lead to a buffer over-read.

    Published: 10 Jul 2008
    7.5
    High

    CVE-2008-3115

    Last Modified: 23 Apr 2026

    Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which might allow remote attackers to exploit vulnerabilities in these older releases.

    Published: 9 Jul 2008
    9.3
    Critical

    CVE-2008-2244

    Last Modified: 23 Apr 2026

    Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.

    Published: 9 Jul 2008
    4.3
    Medium

    CVE-2008-3088

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category action to index.php.

    Published: 9 Jul 2008
    7.5
    High

    CVE-2008-3089

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute arbitrary SQL commands via the uid parameter.

    Published: 9 Jul 2008
    6.5
    Medium

    CVE-2008-3092

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.

    Published: 9 Jul 2008
    6.5
    Medium

    CVE-2008-3093

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.

    Published: 9 Jul 2008
    4.3
    Medium

    CVE-2008-3094

    Last Modified: 23 Apr 2026

    The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain sensitive information (private group names) via unspecified vectors.

    Published: 9 Jul 2008
    3.5
    Low

    CVE-2008-3095

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jul 2008
    6.5
    Medium

    CVE-2008-3096

    Last Modified: 23 Apr 2026

    The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, which might allow remote attackers to gain privileges.

    Published: 9 Jul 2008
    5
    Medium

    CVE-2008-3087

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to index.php, possibly related to the phpManual module.

    Published: 9 Jul 2008
    7.5
    High

    CVE-2008-3090

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819.

    Published: 9 Jul 2008
    3.5
    Low

    CVE-2008-3091

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jul 2008
    3.5
    Low

    CVE-2008-3097

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.

    Published: 9 Jul 2008
    6.1
    Medium

    CVE-2008-2991

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log.

    Published: 9 Jul 2008
    6.2
    Medium

    CVE-2008-6514

    Last Modified: 23 Apr 2026

    The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.

    Published: 9 Jul 2008
    4.3
    Medium

    CVE-2007-3653

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.

    Published: 9 Jul 2008