CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2008-2391

    Last Modified: 23 Apr 2026

    SubSonic allows remote attackers to bypass pagesize limits and cause a denial of service (CPU consumption) via a pageindex (aka data page number) of -1.

    Published: 21 May 2008
    7.5
    High

    CVE-2008-2393

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 May 2008
    7.5
    High

    CVE-2008-2395

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in thread.php in AlkalinePHP 0.80.00 beta and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 May 2008
    4.3
    Medium

    CVE-2008-2397

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 May 2008
    10
    Critical

    CVE-2008-2241

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in caloggerd in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allows remote attackers to append arbitrary data to arbitrary files via directory traversal sequences in unspecified input fields, which are used in log messages. NOTE: this can be leveraged for code execution in many installation environments by writing to a startup file or configuration file.

    Published: 21 May 2008
    6.8
    Medium

    CVE-2008-2390

    Last Modified: 23 Apr 2026

    Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument.

    Published: 21 May 2008
    7.5
    High

    CVE-2008-2394

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to contact.php and the (2) nid parameter to news.php.

    Published: 21 May 2008
    7.5
    High

    CVE-2008-2396

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter.

    Published: 21 May 2008
    4.3
    Medium

    CVE-2008-2398

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.

    Published: 21 May 2008
    4.4
    Medium

    CVE-2007-5495

    Last Modified: 23 Apr 2026

    sealert in setroubleshoot 2.0.5 allows local users to overwrite arbitrary files via a symlink attack on the sealert.log temporary file.

    Published: 21 May 2008
    1.9
    Low

    CVE-2007-5496

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in setroubleshoot 2.0.5 allows local users to inject arbitrary web script or HTML via a crafted (1) file or (2) process name, which triggers an Access Vector Cache (AVC) log entry in a log file used during composition of HTML documents for sealert.

    Published: 21 May 2008
    6.8
    Medium

    CVE-2008-1804

    Last Modified: 23 Apr 2026

    preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.

    Published: 21 May 2008
    4.3
    Medium

    CVE-2008-2419

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.

    Published: 21 May 2008
    7.1
    High

    CVE-2007-5962

    Last Modified: 23 Apr 2026

    Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.

    Published: 21 May 2008
    7.5
    High

    CVE-2008-2347

    Last Modified: 23 Apr 2026

    MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2348

    Last Modified: 23 Apr 2026

    MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a direct request to admin/adduser.php.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2349

    Last Modified: 23 Apr 2026

    Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.

    Published: 20 May 2008
    5
    Medium

    CVE-2008-2350

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot) or (2) C: folder sequences in the file parameter.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2353

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.

    Published: 20 May 2008
    5
    Medium

    CVE-2008-2354

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the data export function in testMaker before 3.0p10 allows test authors to obtain access to export data via unknown vectors.

    Published: 20 May 2008
    6.8
    Medium

    CVE-2008-2355

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the msnum parameter in a coment event.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2356

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbitrary SQL commands via the post_id parameter.

    Published: 20 May 2008
    6.8
    Medium

    CVE-2008-0957

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2351

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQL commands via the (1) lang_id and (2) menu_id parameters.

    Published: 20 May 2008
    6.8
    Medium

    CVE-2008-2352

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2346

    Last Modified: 23 Apr 2026

    AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.

    Published: 20 May 2008
    6.5
    Medium

    CVE-2008-3332

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to execute arbitrary code via the value parameter.

    Published: 20 May 2008
    4.3
    Medium

    CVE-2007-5961

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Red Hat Network channel search feature, as used in RHN and Red Hat Network Satellite before 5.0.2, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 20 May 2008
    3.5
    Low

    CVE-2008-3331

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in return_dynamic_filters.php in Mantis before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the filter_target parameter.

    Published: 20 May 2008
    7.5
    High

    CVE-2008-2338

    Last Modified: 23 Apr 2026

    Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2340

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.

    Published: 19 May 2008
    4.3
    Medium

    CVE-2008-2344

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 May 2008
    10
    Critical

    CVE-2008-2345

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary PHP code via unspecified vectors related to "insufficient file filtering."

    Published: 19 May 2008
    5
    Medium

    CVE-2008-2342

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2336

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 19 May 2008
    4.3
    Medium

    CVE-2008-2335

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2337

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kategoria parameter to (a) galeria.php and the (2) id_phot parameter to (b) popup/koment.php and (c) popup/opis.php in, different vectors than CVE-2006-3163.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2343

    Last Modified: 23 Apr 2026

    News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2334

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in W1L3D4 Philboard 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) forumid parameter to (a) admin/philboard_admin-forumedit.asp, (b) admin/philboard_admin-forum.asp, and (c) W1L3D4_foruma_yeni_konu_ac.asp; the (2) id parameter to (d) W1L3D4_konuoku.asp and (e) W1L3D4_konuya_mesaj_yaz.asp; and the (3) topic parameter to W1L3D4_konuya_mesaj_yaz.asp, different vectors than CVE-2008-1939, CVE-2007-2641, and CVE-2007-0920. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 May 2008
    7.5
    High

    CVE-2008-2341

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.

    Published: 19 May 2008
    9.3
    Critical

    CVE-2008-1949

    Last Modified: 23 Apr 2026

    The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already been processed, which allows remote attackers to cause a denial of service (NULL dereference and crash) via a TLS message containing multiple Client Hello messages, aka GNUTLS-SA-2008-1-2.

    Published: 19 May 2008
    10
    Critical

    CVE-2008-1948

    Last Modified: 23 Apr 2026

    The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero value for the length of Server Names, which leads to a buffer overflow in session resumption data in the pack_security_parameters function, aka GNUTLS-SA-2008-1-1.

    Published: 19 May 2008
    5
    Medium

    CVE-2008-1950

    Last Modified: 23 Apr 2026

    Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-read and crash) via a certain integer value in the Random field in an encrypted Client Hello message within a TLS record with an invalid Record Length, which leads to an invalid cipher padding length, aka GNUTLS-SA-2008-1-3.

    Published: 19 May 2008
    6.8
    Medium

    CVE-2008-2357

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c in glibc and the proper fix should be in glibc; if so, then this should not be treated as a vulnerability in mtr.

    Published: 19 May 2008
    9
    Critical

    CVE-2008-2392

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.

    Published: 19 May 2008
    6.8
    Medium

    CVE-2008-2420

    Last Modified: 23 Apr 2026

    The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.

    Published: 19 May 2008
    5
    Medium

    CVE-2008-2285

    Last Modified: 23 Apr 2026

    The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2286

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.

    Published: 18 May 2008
    7.2
    High

    CVE-2008-2287

    Last Modified: 23 Apr 2026

    Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse.

    Published: 18 May 2008