CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2008-0843

    Last Modified: 23 Apr 2026

    StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.

    Published: 20 Feb 2008
    4.3
    Medium

    CVE-2008-0837

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the log feature in the John Godley Search Unleashed 0.2.10 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, which is not properly handled when the administrator views the log file.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0839

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0844

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0835

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0845

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the person parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0831

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) user_id or (2) category_id parameter. NOTE: this might overlap CVE-2008-0754.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0833

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0832

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0830

    Last Modified: 23 Apr 2026

    The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.

    Published: 19 Feb 2008
    10
    Critical

    CVE-2007-6319

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or (2) access arbitrary mailing lists via unknown vectors related to modification of client-side information; and (3) allow remote authenticated administrators to modify other account data by creating "new accounts that collide with existing accounts."

    Published: 19 Feb 2008
    4.3
    Medium

    CVE-2008-0828

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) attributes such as style and onmouseover in (a) forum post or (b) mail; or (2) the website field of the profile.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0827

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0829

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task.

    Published: 19 Feb 2008
    3.6
    Low

    CVE-2008-0819

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 19 Feb 2008
    4.3
    Medium

    CVE-2008-0820

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER['PHP_INFO']. NOTE: the vendor disputes this issue in a followup, stating that the affected variable is $_SERVER['PHP_SELF'], and "This is not an Etomite specific exploit and I would like the report rescinded.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0821

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attackers to execute arbitrary SQL commands via the questid parameter in an expand_question action.

    Published: 19 Feb 2008
    3.6
    Low

    CVE-2008-0822

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 19 Feb 2008
    10
    Critical

    CVE-2008-0823

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors.

    Published: 19 Feb 2008
    10
    Critical

    CVE-2008-0824

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the php2phps function in Claroline before 1.8.9 has unknown impact and attack vectors.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0825

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Claroline before 1.8.9 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0818

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie to (1) comment.php, (2) index.php, and (3) show.php.

    Published: 19 Feb 2008
    4.3
    Medium

    CVE-2008-0826

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Claroline before 1.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0810

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0811

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php.

    Published: 19 Feb 2008
    6.4
    Medium

    CVE-2008-0812

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the action parameter.

    Published: 19 Feb 2008
    5
    Medium

    CVE-2008-0813

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.

    Published: 19 Feb 2008
    6.4
    Medium

    CVE-2008-0814

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the upload_filename parameter.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0816

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0815

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task.

    Published: 19 Feb 2008
    7.5
    High

    CVE-2008-0817

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.

    Published: 19 Feb 2008
    4.3
    Medium

    CVE-2008-0809

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the htmlscrubber in Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web script or HTML via title contents.

    Published: 19 Feb 2008
    4.3
    Medium

    CVE-2008-0808

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags.

    Published: 19 Feb 2008
    4.7
    Medium

    CVE-2008-0928

    Last Modified: 23 Apr 2026

    Qemu 0.9.1 and earlier does not perform range checks for block device read or write requests, which allows guest host users with root privileges to access arbitrary memory and escape the virtual machine.

    Published: 19 Feb 2008
    6.8
    Medium

    CVE-2008-0804

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter.

    Published: 18 Feb 2008
    7.5
    High

    CVE-2008-0556

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users via a link or IMG tag to RAServer.

    Published: 18 Feb 2008
    7.5
    High

    CVE-2007-6258

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2) Hostname within a Host header.

    Published: 18 Feb 2008
    9.3
    Critical

    CVE-2008-0805

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures.

    Published: 18 Feb 2008
    3.6
    Low

    CVE-2008-0806

    Last Modified: 23 Apr 2026

    wyrd 1.4.3b allows local users to overwrite arbitrary files via a symlink attack on the wyrd-tmp.[USERID] temporary file.

    Published: 18 Feb 2008
    7.5
    High

    CVE-2008-0796

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0802

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0795

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0799

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0800

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0803

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the sys_conf[path][real] parameter to (1) modules\class\Table.php; (2) db_admins.php, (3) db_alert.php, (4) db_double.php, (5) db_games.php, (6) db_matches.php, (7) db_match_teams.php, (8) db_news.php, (9) db_platform.php, (10) db_players.php, (11) db_server_group.php, (12) db_server_ip.php, (13) db_teams.php, (14) db_team_players.php, (15) db_tournaments.php, (16) db_tournament_teams.php, and (17) db_trees.php in modules\class\db\; and (18) Match.php, (19) MatchTeam.php, (20) Rule.php, (21) RuleBuilder.php, (22) RulePool.php, (23) RuleSingle.php, (24) RuleTree.php, (25) Tournament.php, (26) TournamentTeam.php, (27) Tree.php, and (28) TreeSingle.php in modules\class\tournament\. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

    Published: 15 Feb 2008
    5
    Medium

    CVE-2008-0797

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in lib/download.php in iTheora 1.0 rc1 allows remote attackers to read arbitrary files via directory traversal sequences in the url parameter.

    Published: 15 Feb 2008
    4.3
    Medium

    CVE-2008-0798

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ta parameter to artmedic_index.php, reached through index.php; and the (2) date parameter to artmedic_print.php.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0801

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.

    Published: 15 Feb 2008
    10
    Critical

    CVE-2008-0528

    Last Modified: 23 Apr 2026

    Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data.

    Published: 15 Feb 2008
    10
    Critical

    CVE-2008-0530

    Last Modified: 23 Apr 2026

    Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.

    Published: 15 Feb 2008