CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-3034

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) IdFlux parameter to admin/fonctions/supprimer_flux.php and the (2) IdTag parameter to admin/fonctions/supprimer_tag.php.

    Published: 7 Jul 2008
    6.5
    Medium

    CVE-2008-3035

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.

    Published: 7 Jul 2008
    4.3
    Medium

    CVE-2008-3037

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3038

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3039

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    5
    Medium

    CVE-2008-3040

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3041

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "broken access control."

    Published: 7 Jul 2008
    10
    Critical

    CVE-2008-3042

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Improper Error Handling."

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3043

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary code via vectors related to "certain file types."

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3048

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Unprotected test functionality."

    Published: 7 Jul 2008
    5
    Medium

    CVE-2008-3049

    Last Modified: 23 Apr 2026

    The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.

    Published: 7 Jul 2008
    5
    Medium

    CVE-2008-3050

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to cause a denial of service via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3051

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3054

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mh_branchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3055

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Support view (ext_tbl) extension 0.0.102 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3056

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Codeon Petition (cd_petition) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    4.3
    Medium

    CVE-2008-3028

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Send-A-Card (sr_sendcard) extension 2.2.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3046

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in the Packman (kb_packman) extension 0.2.1 and earlier for TYPO3 has unknown impact and attack vectors.

    Published: 7 Jul 2008
    4.3
    Medium

    CVE-2008-3029

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3047

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in the KB Unpack (kb_unpack) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3052

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3053

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3044

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the News Calendar (newscalendar) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3045

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Industry Database (aka Branchendatenbank pro_industrydb) extension 1.0.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Insufficient Verification of Data Authenticity."

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3027

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the article_ID parameter to index.php.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3036

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.

    Published: 7 Jul 2008
    9.3
    Critical

    CVE-2008-3033

    Last Modified: 23 Apr 2026

    RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3022

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitrary PHP code via a URL in (1) icerikyolu, (2) sayfaid, and (3) uzanti parameters.

    Published: 7 Jul 2008
    4.3
    Medium

    CVE-2008-3023

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2005-1799.

    Published: 7 Jul 2008
    9.3
    Critical

    CVE-2008-3024

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-2950

    Last Modified: 23 Apr 2026

    The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.

    Published: 7 Jul 2008
    2.1
    Low

    CVE-2008-3067

    Last Modified: 23 Apr 2026

    sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.

    Published: 4 Jul 2008
    6.8
    Medium

    CVE-2008-2927

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin before 2.4.3 and Adium before 1.3 allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, a different vulnerability than CVE-2008-2955.

    Published: 4 Jul 2008
    9.3
    Critical

    CVE-2008-3001

    Last Modified: 23 Apr 2026

    The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.

    Published: 3 Jul 2008
    6.8
    Medium

    CVE-2008-3000

    Last Modified: 23 Apr 2026

    The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions.

    Published: 3 Jul 2008
    4.3
    Medium

    CVE-2008-2994

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.

    Published: 3 Jul 2008
    7.5
    High

    CVE-2008-2993

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) fog_lang and (2) fog_skin parameters, probably related to libs/required/share.inc; and possibly the (3) fog_pseudo, (4) fog_posted, (5) fog_password, and (6) fog_cook parameters.

    Published: 3 Jul 2008
    7.5
    High

    CVE-2008-2999

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Jul 2008
    4.3
    Medium

    CVE-2008-2998

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jul 2008
    4.3
    Medium

    CVE-2008-2997

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action.

    Published: 3 Jul 2008
    6.8
    Medium

    CVE-2008-2996

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a getsearch action, and the (2) board_id parameter in a viewboard action.

    Published: 3 Jul 2008
    7.5
    High

    CVE-2008-2995

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to execute arbitrary SQL commands via (1) the annuaire parameter to annuaire.php or (2) the username field in admin/login.php.

    Published: 3 Jul 2008
    4.6
    Medium

    CVE-2008-4098

    Last Modified: 23 Apr 2026

    MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.

    Published: 3 Jul 2008
    5
    Medium

    CVE-2008-3215

    Last Modified: 23 Apr 2026

    libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: this issue exists because of an incomplete fix for CVE-2008-2713.

    Published: 3 Jul 2008
    7.5
    High

    CVE-2008-2990

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compath parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2984

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2976

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) language parameter to (a) include_me.php, (b) admin/ajax.php, and (c) admin/objects/catalog.ajaxhandler.php; and the (2) prefix parameter to (d) admin/inc/config.php.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2968

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rating.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the book_id parameter.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2986

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2978

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the prefix parameter.

    Published: 2 Jul 2008