CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-1137

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 4 Mar 2008
    6.4
    Medium

    CVE-2008-1134

    Last Modified: 23 Apr 2026

    OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.

    Published: 4 Mar 2008
    5
    Medium

    CVE-2008-1135

    Last Modified: 23 Apr 2026

    OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames.

    Published: 4 Mar 2008
    9.3
    Critical

    CVE-2008-1136

    Last Modified: 23 Apr 2026

    The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary commands via shell metacharacters in a certain string to TCP port 5679.

    Published: 4 Mar 2008
    10
    Critical

    CVE-2007-6703

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in vdccm before 0.10.1 in SynCE (SynCE-dccm) might allow attackers to cause a denial of service via unspecified vectors.

    Published: 4 Mar 2008
    5
    Medium

    CVE-2007-6702

    Last Modified: 23 Apr 2026

    goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603.

    Published: 4 Mar 2008
    7.5
    High

    CVE-2008-1079

    Last Modified: 23 Apr 2026

    The outboxWriteUnsent function in FTPThread.class in SendFile.jar for Beehive Software SendFile.NET uses hard-coded credentials for an FTP server, which allows remote attackers to gain privileges.

    Published: 4 Mar 2008
    4.3
    Medium

    CVE-2008-1133

    Last Modified: 23 Apr 2026

    The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

    Published: 4 Mar 2008
    6.6
    Medium

    CVE-2008-1130

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.

    Published: 4 Mar 2008
    3.5
    Low

    CVE-2008-1131

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.

    Published: 4 Mar 2008
    4.7
    Medium

    CVE-2008-1132

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in src/mainwindow.c in Net Activity Viewer 0.2.1 allows local users with Net Activity Viewer privileges to execute arbitrary code via a malicious gksu program, which is invoked during the Restart As Root action.

    Published: 4 Mar 2008
    4.3
    Medium

    CVE-2008-1129

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Mar 2008
    4.4
    Medium

    CVE-2008-1199

    Last Modified: 23 Apr 2026

    Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.

    Published: 4 Mar 2008
    6.3
    Medium

    CVE-2008-0931

    Last Modified: 23 Apr 2026

    w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitrary commands or cause a denial of service by modifying the file.

    Published: 4 Mar 2008
    7.2
    High

    CVE-2008-0930

    Last Modified: 23 Apr 2026

    w_editeur.c in XWine 1.0.1 for Debian GNU/Linux allows local users to overwrite or print arbitrary files via a symlink attack on the temporaire temporary file. NOTE: some of these details are obtained from third party information.

    Published: 4 Mar 2008
    3.7
    Low

    CVE-2008-1142

    Last Modified: 23 Apr 2026

    rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

    Published: 4 Mar 2008
    6
    Medium

    CVE-2008-1127

    Last Modified: 23 Apr 2026

    Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered when the game character is killed.

    Published: 3 Mar 2008
    6.8
    Medium

    CVE-2008-1128

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 3 Mar 2008
    5
    Medium

    CVE-2008-1119

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.

    Published: 3 Mar 2008
    6.8
    Medium

    CVE-2008-1123

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the CarpPath parameter to (1) files/carprss.php and (2) files/amazon-bestsellers.php.

    Published: 3 Mar 2008
    5
    Medium

    CVE-2008-1125

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) theme_path parameter to core/themes.php and the (2) filename parameter to download.php.

    Published: 3 Mar 2008
    6.8
    Medium

    CVE-2008-1126

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the pageURL parameter.

    Published: 3 Mar 2008
    7.5
    High

    CVE-2008-1121

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the session_vars cookie.

    Published: 3 Mar 2008
    9.3
    Critical

    CVE-2008-1120

    Last Modified: 23 Apr 2026

    Format string vulnerability in the embedded Internet Explorer component for Mirabilis ICQ 6 build 6043 allows remote servers to execute arbitrary code or cause a denial of service (crash) via unspecified vectors related to HTML code generation.

    Published: 3 Mar 2008
    7.5
    High

    CVE-2008-1122

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL commands via the categ parameter to index.php. NOTE: it was later reported that this also affects Koobi CMS 4.2.4, 4.2.5, and 4.3.0.

    Published: 3 Mar 2008
    6.8
    Medium

    CVE-2008-1124

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3) categories.php, (4) categories_add.php, (5) categories_remove.php, (6) edit.php, (7) editdel.php, (8) ftpfeature.php, (9) login.php, (10) pgRSSnews.php, (11) showcat.php, and (12) upload.php in core/admin/; and (13) archive_cat.php, (14) archive_nocat.php, and (15) recent_list.php in core/.

    Published: 3 Mar 2008
    6.8
    Medium

    CVE-2007-6252

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Learn2 Corporation STRunner (aka Street Technologies) ActiveX control in iestm32.dll allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 3 Mar 2008
    Unknown

    CVE-2008-1112

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-0928. Reason: This candidate is a duplicate of CVE-2008-0928. Notes: All CVE users should reference CVE-2008-0928 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Mar 2008
    7.8
    High

    CVE-2008-1113

    Last Modified: 23 Apr 2026

    Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.

    Published: 3 Mar 2008
    4.3
    Medium

    CVE-2008-1114

    Last Modified: 23 Apr 2026

    Vocera Communications wireless handsets, when using Protected Extensible Authentication Protocol (PEAP), do not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.

    Published: 3 Mar 2008
    9.3
    Critical

    CVE-2008-1116

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information.

    Published: 3 Mar 2008
    4.9
    Medium

    CVE-2008-1115

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Solaris 8 directory functions allows local users to cause a denial of service (panic) via an unspecified sequence of system calls or commands.

    Published: 3 Mar 2008
    5
    Medium

    CVE-2008-1145

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.

    Published: 3 Mar 2008
    5.1
    Medium

    CVE-2008-1149

    Last Modified: 23 Apr 2026

    phpMyAdmin before 2.11.5 accesses $_REQUEST to obtain some parameters instead of $_GET and $_POST, which allows attackers in the same domain to override certain variables and conduct SQL injection and Cross-Site Request Forgery (CSRF) attacks by using crafted cookies.

    Published: 1 Mar 2008
    7.5
    High

    CVE-2008-0385

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in server/widgetallocator.php in Urulu 2.1 allows remote attackers to execute arbitrary SQL commands via the connectionId parameter to index.php with (1) statprt/js/request or (2) dyn/js/request in the PATH_INFO.

    Published: 29 Feb 2008
    Unknown

    CVE-2008-0886

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-0882. Reason: This candidate is a duplicate of CVE-2008-0882. Notes: All CVE users should reference CVE-2008-0882 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Feb 2008
    6.8
    Medium

    CVE-2008-1110

    Last Modified: 23 Apr 2026

    Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted ASF header. NOTE: this issue leads to a crash when an attack uses the CVE-2006-1664 exploit code, but it is different from CVE-2006-1664.

    Published: 29 Feb 2008
    9.3
    Critical

    CVE-2007-6016

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, or (19) _MonthText11 property value when executing the Save method. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.

    Published: 29 Feb 2008
    5.1
    Medium

    CVE-2007-6017

    Last Modified: 23 Apr 2026

    The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash), or create or overwrite arbitrary files, via string values of the (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, and (19) _MonthText11 properties. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.

    Published: 29 Feb 2008
    6.8
    Medium

    CVE-2008-1095

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.

    Published: 29 Feb 2008
    6.8
    Medium

    CVE-2008-1080

    Last Modified: 23 Apr 2026

    Opera before 9.26 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename into a file input.

    Published: 29 Feb 2008
    4.3
    Medium

    CVE-2008-1082

    Last Modified: 23 Apr 2026

    Opera before 9.26 allows remote attackers to "bypass sanitization filters" and conduct cross-site scripting (XSS) attacks via crafted attribute values in an XML document, which are not properly handled during DOM presentation.

    Published: 29 Feb 2008
    6.4
    Medium

    CVE-2008-0303

    Last Modified: 23 Apr 2026

    The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent proxy via a modified PORT command, aka FTP bounce.

    Published: 29 Feb 2008
    6.8
    Medium

    CVE-2008-1081

    Last Modified: 23 Apr 2026

    Opera before 9.26 allows user-assisted remote attackers to execute arbitrary script via images that contain custom comments, which are treated as script when the user displays the image properties.

    Published: 29 Feb 2008
    4.3
    Medium

    CVE-2008-1075

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Maian Cart 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search command. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Feb 2008
    4.3
    Medium

    CVE-2008-1076

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Feb 2008
    7.5
    High

    CVE-2008-1077

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Simpleboard (com_simpleboard) 1.0.3 Stable component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a view action.

    Published: 29 Feb 2008
    6.8
    Medium

    CVE-2008-1074

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[PREPEND_FILE] parameter.

    Published: 29 Feb 2008
    4.3
    Medium

    CVE-2008-1073

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the report interface in Internet Security Systems (ISS) Internet Scanner 7.0 Service Pack 2 Build 7.2.2005.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Feb 2008
    6.8
    Medium

    CVE-2008-1069

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) server_request.php and (2) qlib/smarty.inc.php.

    Published: 28 Feb 2008