CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2008-1918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.

    Published: 22 Apr 2008
    7.5
    High

    CVE-2008-1919

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.

    Published: 22 Apr 2008
    7.5
    High

    CVE-2008-1920

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted personal status message.

    Published: 22 Apr 2008
    7.5
    High

    CVE-2008-1921

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.

    Published: 22 Apr 2008
    5
    Medium

    CVE-2008-1999

    Last Modified: 23 Apr 2026

    Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.

    Published: 22 Apr 2008
    7.5
    High

    CVE-2008-1915

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Apr 2008
    4.3
    Medium

    CVE-2008-1917

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location parameter to browser/code.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Apr 2008
    4.3
    Medium

    CVE-2008-2000

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.

    Published: 22 Apr 2008
    4.9
    Medium

    CVE-2007-5498

    Last Modified: 23 Apr 2026

    The Xen hypervisor block backend driver for Linux kernel 2.6.18, when running on a 64-bit host with a 32-bit paravirtualized guest, allows local privileged users in the guest OS to cause a denial of service (host OS crash) via a request that specifies a large number of blocks.

    Published: 22 Apr 2008
    9.3
    Critical

    CVE-2008-1912

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.

    Published: 22 Apr 2008
    4.3
    Medium

    CVE-2008-1897

    Last Modified: 23 Apr 2026

    The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.

    Published: 22 Apr 2008
    7.5
    High

    CVE-2008-1913

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the new parameter in a new action.

    Published: 22 Apr 2008
    10
    Critical

    CVE-2008-1914

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080. NOTE: some of these details are obtained from third party information.

    Published: 22 Apr 2008
    4.3
    Medium

    CVE-2008-1916

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text fields intended for the (1) address and (2) order information, which are later displayed on the order view page and unspecified other administrative pages, a different vulnerability than CVE-2008-1428.

    Published: 22 Apr 2008
    5
    Medium

    CVE-2008-1928

    Last Modified: 23 Apr 2026

    Buffer overflow in Imager 0.42 through 0.63 allows attackers to cause a denial of service (crash) via an image based fill in which the number of input channels is different from the number of output channels.

    Published: 22 Apr 2008
    4.3
    Medium

    CVE-2008-1974

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 22 Apr 2008
    7.5
    High

    CVE-2008-1909

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 21 Apr 2008
    10
    Critical

    CVE-2008-1910

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers to execute arbitrary code via a malformed opcode 0x52 request to TCP port 3050. NOTE: this might overlap CVE-2007-5243 or CVE-2007-5244.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1904

    Last Modified: 23 Apr 2026

    Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.

    Published: 21 Apr 2008
    4.3
    Medium

    CVE-2008-1906

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year action.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1907

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.

    Published: 21 Apr 2008
    6.8
    Medium

    CVE-2008-1911

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a cookpass cookie.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1903

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

    Published: 21 Apr 2008
    5
    Medium

    CVE-2008-1905

    Last Modified: 23 Apr 2026

    NMMediaServer.exe in Nero MediaHome 3.3.3.0 and earlier, as used in Nero 8.3.2.1 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long HTTP request to TCP port 54444, a different vector than CVE-2007-2322.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1908

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1900

    Last Modified: 23 Apr 2026

    option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field.

    Published: 21 Apr 2008
    7.2
    High

    CVE-2008-1901

    Last Modified: 23 Apr 2026

    aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.

    Published: 21 Apr 2008
    5
    Medium

    CVE-2008-1902

    Last Modified: 23 Apr 2026

    The GUI for aptlinex before 0.91 does not sufficiently warn the user of potentially dangerous actions, which allows remote attackers to remove or modify packages via an apt:// URL.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1613

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.

    Published: 21 Apr 2008
    9.3
    Critical

    CVE-2008-1898

    Last Modified: 23 Apr 2026

    A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.

    Published: 21 Apr 2008
    9
    Critical

    CVE-2008-1436

    Last Modified: 23 Apr 2026

    Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.

    Published: 21 Apr 2008
    7.5
    High

    CVE-2008-1926

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

    Published: 21 Apr 2008
    4.3
    Medium

    CVE-2008-0165

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.

    Published: 20 Apr 2008
    6.8
    Medium

    CVE-2008-1937

    Last Modified: 23 Apr 2026

    The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, which allows remote attackers to gain privileges.

    Published: 20 Apr 2008
    4.3
    Medium

    CVE-2008-1892

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bs_auth.php in Blogator-script 0.95 and 1.01 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2008
    7.5
    High

    CVE-2008-1893

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilang parameter.

    Published: 18 Apr 2008
    7.5
    High

    CVE-2008-1895

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action.

    Published: 18 Apr 2008
    4.3
    Medium

    CVE-2008-1896

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.

    Published: 18 Apr 2008
    7.5
    High

    CVE-2008-1889

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in XplodPHP AutoTutorials 2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Apr 2008
    7.5
    High

    CVE-2008-1890

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Apr 2008
    4.3
    Medium

    CVE-2008-1894

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in desktoplaunch/InfoView/logon/logon.object in BusinessObjects InfoView XI R2 SP1, SP2, and SP3 Java version before FixPack 3.5 allows remote attackers to inject arbitrary web script or HTML via the cms parameter.

    Published: 18 Apr 2008
    4.3
    Medium

    CVE-2008-1888

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.

    Published: 18 Apr 2008
    6.8
    Medium

    CVE-2008-1883

    Last Modified: 23 Apr 2026

    The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and instead sends an arbitrary MD5 string.

    Published: 18 Apr 2008
    5
    Medium

    CVE-2008-1884

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to read arbitrary files via directory traversal sequences in the wiki parameter, a different vector than CVE-2006-4418.

    Published: 18 Apr 2008
    3.6
    Low

    CVE-2008-1734

    Last Modified: 23 Apr 2026

    Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.

    Published: 18 Apr 2008
    7.5
    High

    CVE-2008-1886

    Last Modified: 23 Apr 2026

    The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by calculating the required KeyCode. NOTE: this can be used by arbitrary web sites to host exploit code that targets this control.

    Published: 18 Apr 2008
    6.8
    Medium

    CVE-2008-1885

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a .. (dot dot) in the SkinPath parameter and a .zip URL in the HttpSkin parameter. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 18 Apr 2008
    6.8
    Medium

    CVE-2008-1881

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.

    Published: 17 Apr 2008
    2.1
    Low

    CVE-2008-1877

    Last Modified: 23 Apr 2026

    tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1864

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter.

    Published: 17 Apr 2008