CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-1251

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Mar 2008
    5.8
    Medium

    CVE-2008-1248

    Last Modified: 23 Apr 2026

    The web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to make arbitrary phone calls via the "Call a number" field. NOTE: this might overlap CVE-2007-3440.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1256

    Last Modified: 23 Apr 2026

    The ZyXEL P-660HW series router has "admin" as its default password, which allows remote attackers to gain administrative access.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1258

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in prim.htm on the D-Link DI-604 router allows remote attackers to inject arbitrary web script or HTML via the rf parameter.

    Published: 10 Mar 2008
    9.3
    Critical

    CVE-2008-1259

    Last Modified: 23 Apr 2026

    The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within the previous 5 minutes.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1255

    Last Modified: 23 Apr 2026

    The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user.

    Published: 10 Mar 2008
    7.5
    High

    CVE-2008-1264

    Last Modified: 23 Apr 2026

    The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a file that lists all HTML documents, and an ELF executable file.

    Published: 10 Mar 2008
    7.8
    High

    CVE-2008-1265

    Last Modified: 23 Apr 2026

    The Linksys WRT54G router allows remote attackers to cause a denial of service (device restart) via a long username and password to the FTP interface.

    Published: 10 Mar 2008
    7.8
    High

    CVE-2008-1266

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the web interface on the D-Link DI-524 router allow remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact via (1) a long username or (2) an HTTP header with a large name and an empty value.

    Published: 10 Mar 2008
    7.8
    High

    CVE-2008-1267

    Last Modified: 23 Apr 2026

    The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interface crash) via an HTTP request to basehelp_English.htm with a large integer in the Content-Length field.

    Published: 10 Mar 2008
    7.5
    High

    CVE-2008-1223

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 10 Mar 2008
    9.3
    Critical

    CVE-2008-1231

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1247

    Last Modified: 23 Apr 2026

    The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary administrative actions via a direct request to (1) Advanced.tri, (2) AdvRoute.tri, (3) Basic.tri, (4) ctlog.tri, (5) ddns.tri, (6) dmz.tri, (7) factdefa.tri, (8) filter.tri, (9) fw.tri, (10) manage.tri, (11) ping.tri, (12) PortRange.tri, (13) ptrigger.tri, (14) qos.tri, (15) rstatus.tri, (16) tracert.tri, (17) vpn.tri, (18) WanMac.tri, (19) WBasic.tri, or (20) WFilter.tri. NOTE: the Security.tri vector is already covered by CVE-2006-5202.

    Published: 10 Mar 2008
    6.8
    Medium

    CVE-2008-1254

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities on the ZyXEL P-660HW series router allow remote attackers to (1) change DNS servers and (2) add keywords to the "bannedlist" via unspecified vectors.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1268

    Last Modified: 23 Apr 2026

    The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to establish an FTP session by sending an arbitrary username and password.

    Published: 10 Mar 2008
    7.1
    High

    CVE-2008-1269

    Last Modified: 23 Apr 2026

    cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attackers to disable Wi-Fi encryption via a certain request.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1224

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrary web script or HTML via the returnTo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Mar 2008
    7.8
    High

    CVE-2008-1246

    Last Modified: 23 Apr 2026

    The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing these characters via the Backspace key, and then holding down the Backspace key for one second after erasing the final character. NOTE: third parties, including one who works for the vendor, have been unable to reproduce the flaw unless the enable password is blank

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1257

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Forms/DiagGeneral_2 on the ZyXEL P-660HW series router allows remote attackers to inject arbitrary web script or HTML via the PingIPAddr parameter.

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1261

    Last Modified: 23 Apr 2026

    The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware provides different responses to admin page requests depending on whether a user is logged in, which allows remote attackers to obtain current login status by requesting an arbitrary admin URI.

    Published: 10 Mar 2008
    4
    Medium

    CVE-2008-1263

    Last Modified: 23 Apr 2026

    The Linksys WRT54G router stores passwords and keys in cleartext in the Config.bin file, which might allow remote authenticated users to obtain sensitive information via an HTTP request for the top-level Config.bin URI.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1222

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Mar 2008
    9.3
    Critical

    CVE-2008-1230

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page."

    Published: 10 Mar 2008
    7.8
    High

    CVE-2008-1245

    Last Modified: 23 Apr 2026

    cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1252

    Last Modified: 23 Apr 2026

    b_banner.stm (aka the login page) on the Deutsche Telekom Speedport W500 DSL router allows remote attackers to obtain the logon password by reading the pwd field in the HTML source.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1253

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the D-Link DSL-G604T router allows remote attackers to inject arbitrary web script or HTML via the var:category parameter, as demonstrated by a request for advanced/portforw.htm on the fwan page.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1260

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities on the Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware allow remote attackers to (1) make the admin web server available on the Internet (WAN) interface via the WWWAccessInterface parameter to Forms/RemMagWWW_1 or (2) change the IP whitelisting timeout via the StdioTimout parameter to Forms/rpSysAdmin_1.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1262

    Last Modified: 23 Apr 2026

    The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.

    Published: 10 Mar 2008
    3.3
    Low

    CVE-2007-6705

    Last Modified: 23 Apr 2026

    The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.

    Published: 9 Mar 2008
    9.3
    Critical

    CVE-2007-6706

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.

    Published: 9 Mar 2008
    9.3
    Critical

    CVE-2008-1217

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706.

    Published: 9 Mar 2008
    4.6
    Medium

    CVE-2008-1215

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.

    Published: 9 Mar 2008
    6.8
    Medium

    CVE-2008-1216

    Last Modified: 23 Apr 2026

    IBM Lotus Quickr 8.0 server, and possibly QuickPlace 7.x, does not properly identify URIs containing cross-site scripting (XSS) attack strings, which allows remote attackers to inject arbitrary web script or HTML via a Calendar OpenDocument action to main.nsf with a Count parameter containing a JavaScript event in a malformed element, as demonstrated by an onload event in an IFRAME element.

    Published: 9 Mar 2008
    6.8
    Medium

    CVE-2008-1218

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

    Published: 9 Mar 2008
    7.5
    High

    CVE-2008-1214

    Last Modified: 23 Apr 2026

    MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1208

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1209

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in redirect.do in Xitex WebContent M1 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1213

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Numara FootPrints for Linux 8.1 allows remote attackers to inject arbitrary web script or HTML via the Title form field when setting an appointment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1212

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in set_permissions.php in Podcast Generator 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the scriptlang parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1204

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Administration Console in Sun Java System Access Manager 7.1 and 7 2005Q4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) Help and (2) Version windows.

    Published: 8 Mar 2008
    4.9
    Medium

    CVE-2008-1205

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ipsecah kernel module in Sun Solaris 10, when a key management daemon for IPsec security associations is running, allows local users to cause a denial of service (panic) via unspecified vectors.

    Published: 8 Mar 2008
    5
    Medium

    CVE-2008-1207

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Fujitsu Interstage Smart Repository, as used in multiple Fujitsu Interstage products, allow remote attackers to cause a denial of service (daemon crash) via (1) an invalid request or (2) a large amount of data sent to the registered attribute value.

    Published: 8 Mar 2008
    9.3
    Critical

    CVE-2008-1210

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ctags parsing code in Programmer's Notepad before 2.0.8.718 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted .c file, when the victim selects the Jump To dialog. NOTE: some of these details are obtained from third party information.

    Published: 8 Mar 2008
    5
    Medium

    CVE-2008-1652

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the _serve_request_multiple function in lib/Perlbal/ClientHTTPBase.pm in Perlbal before 1.70, when concat get is enabled, allows remote attackers to read arbitrary files in a parent directory via a directory traversal sequence in an unspecified parameter. NOTE: some of these details are obtained from third party information.

    Published: 8 Mar 2008
    6.8
    Medium

    CVE-2008-1206

    Last Modified: 23 Apr 2026

    Format string vulnerability in the log_message function in lks.c in Linux Kiss Server 1.2, when background (daemon) mode is disabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in an invalid command.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1211

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BosDates 3.x and 4.x allows remote attackers to inject arbitrary web script or HTML via (1) the type parameter in calendar.php and (2) the category parameter in calendar_search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Mar 2008
    4.3
    Medium

    CVE-2008-1304

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.

    Published: 7 Mar 2008
    5
    Medium

    CVE-2011-1015

    Last Modified: 11 Apr 2025

    The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

    Published: 7 Mar 2008
    9.3
    Critical

    CVE-2008-1200

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Access allows remote user-assisted attackers to execute arbitrary code via a crafted .MDB file, possibly related to Jet Engine (msjet40.dll). NOTE: this is probably a different issue than CVE-2007-6026.

    Published: 6 Mar 2008
    9.3
    Critical

    CVE-2008-1190

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.

    Published: 6 Mar 2008