CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-2898

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 27 Jun 2008
    10
    Critical

    CVE-2008-2899

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in includes/classes/page.php in j00lean-CMS 1.03 has unknown impact and attack vectors.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2900

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2891

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a category action.

    Published: 27 Jun 2008
    6.8
    Medium

    CVE-2008-2889

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.

    Published: 27 Jun 2008
    5
    Medium

    CVE-2008-2881

    Last Modified: 23 Apr 2026

    Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Published: 26 Jun 2008
    6.4
    Medium

    CVE-2008-2878

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in rss_getfile.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2869

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Published: 26 Jun 2008
    6.8
    Medium

    CVE-2008-2877

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2870

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via the (1) eventID parameter to event_info.php and the (2) userID parameter to list_user.php.

    Published: 26 Jun 2008
    7.8
    High

    CVE-2008-2061

    Last Modified: 23 Apr 2026

    The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.

    Published: 26 Jun 2008
    9.3
    Critical

    CVE-2008-2880

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the IBM AFP Viewer Plug-in 2.0.7.1 and 3.2.1.1 allows remote attackers to execute arbitrary code via a long SRC property value. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jun 2008
    6.4
    Medium

    CVE-2008-2879

    Last Modified: 23 Apr 2026

    Benja CMS 0.1 does not require authentication for access to admin/, which allows remote attackers to add or delete a menu.

    Published: 26 Jun 2008
    4.3
    Medium

    CVE-2008-2871

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jun 2008
    5
    Medium

    CVE-2008-2730

    Last Modified: 23 Apr 2026

    The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843.

    Published: 26 Jun 2008
    5
    Medium

    CVE-2008-2062

    Last Modified: 23 Apr 2026

    The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsq35151.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2867

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2868

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2872

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sayfa parameter.

    Published: 26 Jun 2008
    5
    Medium

    CVE-2008-2873

    Last Modified: 23 Apr 2026

    sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request to Db/urun.mdb.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2874

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2875

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL commands via the hal parameter.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2876

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the zone parameter.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2882

    Last Modified: 23 Apr 2026

    upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a direct request.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2883

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter. NOTE: some of these details are obtained from third party information.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2371

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins with an option and contains multiple branches.

    Published: 26 Jun 2008
    5
    Medium

    CVE-2008-2952

    Last Modified: 23 Apr 2026

    liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.

    Published: 26 Jun 2008
    7.5
    High

    CVE-2008-2860

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Published: 25 Jun 2008
    5
    Medium

    CVE-2008-2859

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2850

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API.

    Published: 25 Jun 2008
    4.3
    Medium

    CVE-2008-2842

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2844

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2845

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2846

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2847

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL commands via the categori parameter in a pocategorisell action to modules.php.

    Published: 25 Jun 2008
    4.3
    Medium

    CVE-2008-2848

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search functionality in MindTouch DekiWiki before 8.05.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Jun 2008
    3.5
    Low

    CVE-2008-2849

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2843

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter in an USUB action to default.asp and the (2) Licence[SpecialLicenseNumber] (aka LicenceId) cookie to edit/default.asp.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2854

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Orlando CMS 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[preloc] parameter to (1) modules/core/logger/init.php and (2) AJAX/newscat.php.

    Published: 25 Jun 2008
    4.3
    Medium

    CVE-2008-2855

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2856

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Jun 2008
    5
    Medium

    CVE-2008-2857

    Last Modified: 23 Apr 2026

    AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Published: 25 Jun 2008
    6.8
    Medium

    CVE-2008-2858

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2862

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2863

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.

    Published: 25 Jun 2008
    5
    Medium

    CVE-2008-2864

    Last Modified: 23 Apr 2026

    eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2865

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2866

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.

    Published: 25 Jun 2008
    4.3
    Medium

    CVE-2008-2861

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp.

    Published: 25 Jun 2008
    10
    Critical

    CVE-2008-2851

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in OFF System before 0.19.14 allow remote attackers to have an unknown impact via unspecified vectors related to "parsing of http headers."

    Published: 25 Jun 2008