CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-2445

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a show action.

    Published: 27 May 2008
    4.3
    Medium

    CVE-2008-2450

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2451

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 May 2008
    4.3
    Medium

    CVE-2008-2452

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Questionaire (aka pbsurvey) extension 1.2.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2453

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2457

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 27 May 2008
    4.3
    Medium

    CVE-2008-2458

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.

    Published: 27 May 2008
    6.8
    Medium

    CVE-2008-2459

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2460

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2461

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Netious CMS 0.4 allows remote attackers to execute arbitrary SQL commands via the pageid parameter, a different vector than CVE-2006-4047.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2447

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2455

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the rid parameter.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2446

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) userid parameter to (a) profile.php in a "show moreinfo" action; the (2) bildid parameter to (b) picturegallery.php in a shownext action; the (3) id parameter to (c) filebase.php in a freigeben action, (d) schedule.php in a del action, and (e) profile.php in an observe action; and the (4) pmid parameter in a delete action and (5) folderid parameter in a showfolder action to (f) message.php.

    Published: 27 May 2008
    4.3
    Medium

    CVE-2008-2449

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to image.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2456

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2448

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.

    Published: 27 May 2008
    7.5
    High

    CVE-2008-2454

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the movie parameter to index.php.

    Published: 27 May 2008
    5.5
    Medium

    CVE-2006-3635

    Last Modified: 20 Apr 2025

    The ia64 subsystem in the Linux kernel before 2.6.26 allows local users to cause a denial of service (stack consumption and system crash) via a crafted application that leverages the mishandling of invalid Register Stack Engine (RSE) state.

    Published: 27 May 2008
    4.3
    Medium

    CVE-2008-2333

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Published: 23 May 2008
    9.3
    Critical

    CVE-2008-2408

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the XML parsing functionality in talk.dll in Cerulean Studios Trillian Pro before 3.1.10.0 allows remote attackers to execute arbitrary code via a malformed attribute in an IMG tag.

    Published: 23 May 2008
    10
    Critical

    CVE-2008-2423

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Interchange before 5.6.0 and before 5.5.2 allows remote attackers to cause a denial of service via crafted HTTP requests. NOTE: this might overlap CVE-2007-2635.

    Published: 23 May 2008
    7.5
    High

    CVE-2008-2425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 May 2008
    10
    Critical

    CVE-2008-2424

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the 404 error page for the "Standard demo" in Interchange before 5.6.0 and before 5.5.2 has unknown impact and attack vectors.

    Published: 23 May 2008
    9.3
    Critical

    CVE-2008-2407

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AIM.DLL in Cerulean Studios Trillian before 3.1.10.0 allows user-assisted remote attackers to execute arbitrary code via a long attribute value in a FONT tag in a message.

    Published: 23 May 2008
    9.3
    Critical

    CVE-2008-2409

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.

    Published: 23 May 2008
    7.5
    High

    CVE-2008-2422

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Web Slider 0.6 allows remote attackers to execute arbitrary SQL commands via the slide parameter in a slides action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 May 2008
    4.3
    Medium

    CVE-2008-2421

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.

    Published: 23 May 2008
    4.7
    Medium

    CVE-2008-2418

    Last Modified: 23 Apr 2026

    Race condition in the STREAMS Administrative Driver (sad) in Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.

    Published: 23 May 2008
    6.8
    Medium

    CVE-2008-2575

    Last Modified: 23 Apr 2026

    cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.

    Published: 23 May 2008
    7.8
    High

    CVE-2008-0535

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device instability) via "SSH credentials that attempt to change the authentication method," aka Bug ID CSCsm14239.

    Published: 22 May 2008
    7.8
    High

    CVE-2008-0536

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers "illegal I/O operations," aka Bug ID CSCsh49563.

    Published: 22 May 2008
    4.3
    Medium

    CVE-2008-2006

    Last Modified: 23 Apr 2026

    Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit integer on a TRIGGER line, or (2) a large integer in a COUNT field on an RRULE line.

    Published: 22 May 2008
    Unknown

    CVE-2008-2007

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1035. Reason: This candidate is a reservation duplicate of CVE-2008-1035. Notes: All CVE users should reference CVE-2008-1035 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 May 2008
    7.2
    High

    CVE-2008-2400

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vectors.

    Published: 22 May 2008
    4.3
    Medium

    CVE-2008-2410

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2008
    7.5
    High

    CVE-2008-2412

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 May 2008
    6.8
    Medium

    CVE-2008-2415

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 22 May 2008
    7.5
    High

    CVE-2008-2416

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter in a Fiction action, possibly related to sources/fiction.class.php.

    Published: 22 May 2008
    10
    Critical

    CVE-2008-2240

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.

    Published: 22 May 2008
    7.8
    High

    CVE-2008-0534

    Last Modified: 23 Apr 2026

    The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582.

    Published: 22 May 2008
    9
    Critical

    CVE-2008-2053

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Unified Customer Voice Portal (CVP) 4.0.x before 4.0(2)_ES14, 4.1.x before 4.1(1)_ES11, and 7.x before 7.0(1) allows remote authenticated users with administrator role privileges to create, modify, or delete a superuser account.

    Published: 22 May 2008
    9.3
    Critical

    CVE-2008-2399

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 22 May 2008
    6.8
    Medium

    CVE-2008-2411

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SazCart 1.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a details action.

    Published: 22 May 2008
    4.3
    Medium

    CVE-2008-2413

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 22 May 2008
    4.3
    Medium

    CVE-2008-2414

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.

    Published: 22 May 2008
    7.5
    High

    CVE-2008-2417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary SQL commands via the qNo parameter.

    Published: 22 May 2008
    7.1
    High

    CVE-2008-1159

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293.

    Published: 22 May 2008
    9.3
    Critical

    CVE-2008-1104

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Foxit Reader before 2.3 build 2912 allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file, related to the util.printf JavaScript function and floating point specifiers in format strings.

    Published: 21 May 2008
    6.3
    Medium

    CVE-2008-1660

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in useradd on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unspecified vectors.

    Published: 21 May 2008
    7.5
    High

    CVE-2008-2242

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function.

    Published: 21 May 2008