CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-2852

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CGIWrap before 4.1, when an Internet Explorer based browser is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to failure to set the charset in error messages.

    Published: 25 Jun 2008
    7.5
    High

    CVE-2008-2853

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.

    Published: 25 Jun 2008
    6.8
    Medium

    CVE-2008-2942

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.

    Published: 25 Jun 2008
    4.9
    Medium

    CVE-2008-0598

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary.

    Published: 25 Jun 2008
    9.3
    Critical

    CVE-2008-2427

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.

    Published: 24 Jun 2008
    10
    Critical

    CVE-2008-2832

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.

    Published: 24 Jun 2008
    5
    Medium

    CVE-2008-2838

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

    Published: 24 Jun 2008
    4.3
    Medium

    CVE-2008-2839

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to index.php.

    Published: 24 Jun 2008
    7.5
    High

    CVE-2008-2834

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Jun 2008
    6.8
    Medium

    CVE-2008-2840

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompage.php, (2) errors/404.php, (3) members/memberslist.php, (4) members/profile.php, (5) news/fullview.php, (6) news/index.php, (7) nopermission.php, (8) usercp/avatar.php, or (9) usercp/editpassword.php in themes/Default/. NOTE: some of these details are obtained from third party information.

    Published: 24 Jun 2008
    10
    Critical

    CVE-2008-2833

    Last Modified: 23 Apr 2026

    admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.

    Published: 24 Jun 2008
    7.5
    High

    CVE-2008-2835

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL commands via the formid parameter.

    Published: 24 Jun 2008
    7.5
    High

    CVE-2008-2837

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.

    Published: 24 Jun 2008
    7.5
    High

    CVE-2008-2836

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the noSet parameter, a different vector than CVE-2007-1483.

    Published: 24 Jun 2008
    4.6
    Medium

    CVE-2008-1951

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-31.el5_2.1 in RHEL 5, allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp, related to an incorrect RPATH setting, as demonstrated by a malicious libc.so library for tog-pegasus.

    Published: 24 Jun 2008
    7.2
    High

    CVE-2008-2830

    Last Modified: 23 Apr 2026

    Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent.

    Published: 23 Jun 2008
    9.3
    Critical

    CVE-2008-2306

    Last Modified: 23 Apr 2026

    Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.

    Published: 23 Jun 2008
    10
    Critical

    CVE-2008-2828

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in tmsnc allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an MSN packet with a UBX command containing a large UBX payload length field.

    Published: 23 Jun 2008
    7.5
    High

    CVE-2008-2815

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Jun 2008
    7.5
    High

    CVE-2008-2816

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

    Published: 23 Jun 2008
    7.5
    High

    CVE-2008-2817

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.

    Published: 23 Jun 2008
    9.3
    Critical

    CVE-2008-2822

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a (1) LIST or (2) MLSD command.

    Published: 23 Jun 2008
    7.5
    High

    CVE-2008-2823

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.

    Published: 23 Jun 2008
    10
    Critical

    CVE-2008-2824

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Extensible Interface Platform in Web Services in Xerox WorkCentre 7655, 7665, and 7675 allows remote attackers to make configuration changes via unknown vectors.

    Published: 23 Jun 2008
    4.3
    Medium

    CVE-2008-2825

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the embedded Web Server in Xerox WorkCentre M123, M128, and 133 and WorkCentre Pro 123, 128, and 133 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Jun 2008
    6.8
    Medium

    CVE-2008-2813

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 23 Jun 2008
    7.5
    High

    CVE-2008-2819

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BlognPlus (BURO GUN +) 2.5.4 and earlier MySQL and PostgreSQL editions allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Jun 2008
    4.3
    Medium

    CVE-2008-2814

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Jun 2008
    6.4
    Medium

    CVE-2008-2820

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 23 Jun 2008
    7.5
    High

    CVE-2008-2818

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the default URI.

    Published: 23 Jun 2008
    9.3
    Critical

    CVE-2008-2821

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.

    Published: 23 Jun 2008
    4.3
    Medium

    CVE-2008-3714

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.

    Published: 23 Jun 2008
    10
    Critical

    CVE-2008-2641

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Reader and Acrobat 7.0.9 and earlier, and 8.0 through 8.1.2, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to an "input validation issue in a JavaScript method."

    Published: 23 Jun 2008
    4.9
    Medium

    CVE-2008-2372

    Last Modified: 23 Apr 2026

    The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly zeroed pages."

    Published: 21 Jun 2008
    4.9
    Medium

    CVE-2008-2826

    Last Modified: 23 Apr 2026

    Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and system outage) via vectors involving a large addr_num field in an sctp_getaddrs_old data structure.

    Published: 21 Jun 2008
    4.3
    Medium

    CVE-2008-2787

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter.

    Published: 20 Jun 2008
    4.3
    Medium

    CVE-2008-2788

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.

    Published: 20 Jun 2008
    7.5
    High

    CVE-2008-2789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Published: 20 Jun 2008
    7.5
    High

    CVE-2008-2792

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter.

    Published: 20 Jun 2008
    7.5
    High

    CVE-2008-2793

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Published: 20 Jun 2008
    6.8
    Medium

    CVE-2008-2794

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via unknown attack vectors.

    Published: 20 Jun 2008
    4.3
    Medium

    CVE-2008-2795

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.

    Published: 20 Jun 2008
    7.5
    High

    CVE-2008-2791

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Jun 2008
    4.3
    Medium

    CVE-2008-2797

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MainLayout.do in ManageEngine OpUtils 5.0 allows remote attackers to inject arbitrary web script or HTML via the hostName parameter, when viewing an SNMP graph. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Jun 2008
    7.5
    High

    CVE-2008-2790

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Jun 2008
    7.5
    High

    CVE-2008-2796

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 20 Jun 2008
    Unknown

    CVE-2008-2727

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-2725. Reason: This candidate is a duplicate of CVE-2008-2725. Notes: All CVE users should reference CVE-2008-2725 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Jun 2008
    10
    Critical

    CVE-2008-2663

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code or cause a denial of service via unknown vectors, a different issue than CVE-2008-2662, CVE-2008-2664, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

    Published: 20 Jun 2008
    7.8
    High

    CVE-2008-2726

    Last Modified: 23 Apr 2026

    Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.

    Published: 20 Jun 2008
    4.6
    Medium

    CVE-2008-2827

    Last Modified: 23 Apr 2026

    The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.

    Published: 20 Jun 2008