CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-2082

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web script or HTML via the module parameter, which leaks the path in an error message.

    Published: 5 May 2008
    9
    Critical

    CVE-2008-2081

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Published: 5 May 2008
    4.3
    Medium

    CVE-2008-2075

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in pic.php in AstroCam 2.5.0 through 2.7.3 allows remote attackers to inject arbitrary web script or HTML via the picfile parameter.

    Published: 5 May 2008
    10
    Critical

    CVE-2008-2077

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Plain Black WebGUI 7.4.34 has unknown impact and attack vectors related to "data form list view."

    Published: 5 May 2008
    7.5
    High

    CVE-2008-2076

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the style parameter.

    Published: 5 May 2008
    7.5
    High

    CVE-2008-2074

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.

    Published: 5 May 2008
    7.5
    High

    CVE-2008-2078

    Last Modified: 23 Apr 2026

    Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of the Robocode game" via unspecified vectors related to the AWT Event Queue.

    Published: 5 May 2008
    7.5
    High

    CVE-2008-2073

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

    Published: 5 May 2008
    4.3
    Medium

    CVE-2008-2072

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or HTML via the l parameter, a different vector than CVE-2006-3260.

    Published: 5 May 2008
    3.5
    Low

    CVE-2008-2105

    Last Modified: 23 Apr 2026

    email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

    Published: 4 May 2008
    4.3
    Medium

    CVE-2008-2103

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.

    Published: 4 May 2008
    4
    Medium

    CVE-2008-2104

    Last Modified: 23 Apr 2026

    The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check.

    Published: 4 May 2008
    7.5
    High

    CVE-2008-2067

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to execute arbitrary SQL commands via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.

    Published: 2 May 2008
    9.3
    Critical

    CVE-2008-2069

    Last Modified: 23 Apr 2026

    Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.

    Published: 2 May 2008
    4.3
    Medium

    CVE-2008-2066

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via the whatus parameter in a searchusers2 action. NOTE: it was later reported that other versions before 3.0.1 are also vulnerable.

    Published: 2 May 2008
    7.5
    High

    CVE-2008-2065

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary SQL commands via the catagorie parameter.

    Published: 2 May 2008
    10
    Critical

    CVE-2008-2064

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems."

    Published: 2 May 2008
    7.5
    High

    CVE-2008-2063

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browse.videos.php in Joovili 3.1 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 2 May 2008
    6.1
    Medium

    CVE-2008-2052

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.

    Published: 2 May 2008
    7.2
    High

    CVE-2008-1675

    Last Modified: 23 Apr 2026

    The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writing kernel memory.

    Published: 2 May 2008
    7.5
    High

    CVE-2008-2085

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the (1) get_remote_ip_media and (2) get_remote_ipv6_media functions in call.cpp in SIPp 3.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted SIP message.

    Published: 2 May 2008
    4.3
    Medium

    CVE-2008-2048

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML via the sayfa parameter.

    Published: 1 May 2008
    4.3
    Medium

    CVE-2008-2049

    Last Modified: 23 Apr 2026

    The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message.

    Published: 1 May 2008
    7.5
    High

    CVE-2008-2047

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hpz/profil.asp and (2) hpz/prodetail.asp.

    Published: 1 May 2008
    4.3
    Medium

    CVE-2008-2046

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 1 May 2008
    5
    Medium

    CVE-2008-2045

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

    Published: 1 May 2008
    7.5
    High

    CVE-2008-2044

    Last Modified: 23 Apr 2026

    includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action to projects_site/uploadfile.php.

    Published: 1 May 2008
    4.3
    Medium

    CVE-2008-2043

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter to frontend/x2/cron/editcronsimple.html, and perform various administrative actions via (2) frontend/x2/sql/adddb.html, (3) frontend/x2/sql/adduser.html, and (4) frontend/x2/ftp/doaddftp.html.

    Published: 1 May 2008
    Unknown

    CVE-2008-6339

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6339. Reason: This candidate is a duplicate of CVE-2007-6339. Notes: All CVE users should reference CVE-2007-6339 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 May 2008
    6.8
    Medium

    CVE-2007-6339

    Last Modified: 23 Apr 2026

    The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters."

    Published: 1 May 2008
    4.9
    Medium

    CVE-2011-3209

    Last Modified: 11 Apr 2025

    The div_long_long_rem implementation in include/asm-x86/div64.h in the Linux kernel before 2.6.26 on the x86 platform allows local users to cause a denial of service (Divide Error Fault and panic) via a clock_gettime system call.

    Published: 1 May 2008
    9.8
    Critical

    CVE-2008-0599

    Last Modified: 23 Apr 2026

    The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.

    Published: 1 May 2008
    6.9
    Medium

    CVE-2008-1375

    Last Modified: 23 Apr 2026

    Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.

    Published: 1 May 2008
    10
    Critical

    CVE-2008-2050

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the FastCGI SAPI (fastcgi.c) in PHP before 5.2.6 has unknown impact and attack vectors.

    Published: 1 May 2008
    10
    Critical

    CVE-2008-2051

    Last Modified: 23 Apr 2026

    The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."

    Published: 1 May 2008
    4.3
    Medium

    CVE-2008-2030

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Apr 2008
    6.8
    Medium

    CVE-2008-2029

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.

    Published: 30 Apr 2008
    3.5
    Low

    CVE-2008-2037

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EditeurScripts EsContacts 1.0 allow remote authenticated users to inject arbitrary web script or HTML via the msg parameter to (1) login.php, (2) importer.php, (3) add_groupe.php, (4) contacts.php, (5) groupes.php, and (6) search.php.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2036

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter in a poll action.

    Published: 30 Apr 2008
    4.3
    Medium

    CVE-2008-2035

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2034

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Apr 2008
    5
    Medium

    CVE-2008-2031

    Last Modified: 23 Apr 2026

    VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Apr 2008
    4.3
    Medium

    CVE-2008-2028

    Last Modified: 23 Apr 2026

    miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.

    Published: 30 Apr 2008
    Unknown

    CVE-2008-2033

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1381. Reason: This candidate is a duplicate of CVE-2008-1381. Notes: All CVE users should reference CVE-2008-1381 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Apr 2008
    6.5
    Medium

    CVE-2008-2038

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2040

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the HTTP::getAuthUserPass function (core/common/http.cpp) in Peercast 0.1218 and gnome-peercast allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Basic Authentication string with a long (1) username or (2) password.

    Published: 30 Apr 2008
    10
    Critical

    CVE-2008-2041

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.

    Published: 30 Apr 2008
    5
    Medium

    CVE-2008-2032

    Last Modified: 23 Apr 2026

    The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Apr 2008
    4.3
    Medium

    CVE-2008-2026

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258, and other versions before 5.3.3.378, allows remote attackers to inject arbitrary web script or HTML via a URL-encoded postdata parameter. NOTE: this is different than CVE-2005-1118, but it might be the same as CVE-2008-1470.

    Published: 30 Apr 2008
    5.8
    Medium

    CVE-2008-2027

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in WebID/IISWebAgentIF.dll in RSA Authentication Agent 5.3.0.258 for Web for IIS, when accessed via certain browsers such as Mozilla Firefox, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an ftp URL in the url parameter to a Redirect action.

    Published: 30 Apr 2008