CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-0471

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.

    Published: 29 Jan 2008
    7.5
    High

    CVE-2008-0469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action.

    Published: 29 Jan 2008
    7.5
    High

    CVE-2008-0468

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 29 Jan 2008
    10
    Critical

    CVE-2008-0477

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method. NOTE: some of these details are obtained from third party information.

    Published: 29 Jan 2008
    4.3
    Medium

    CVE-2008-0474

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Jan 2008
    5
    Medium

    CVE-2008-0480

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.

    Published: 29 Jan 2008
    6.8
    Medium

    CVE-2008-0478

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php.

    Published: 29 Jan 2008
    5
    Medium

    CVE-2008-0479

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.

    Published: 29 Jan 2008
    5
    Medium

    CVE-2008-0481

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.

    Published: 29 Jan 2008
    4.3
    Medium

    CVE-2008-0472

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.

    Published: 29 Jan 2008
    6.4
    Medium

    CVE-2008-0476

    Last Modified: 23 Apr 2026

    ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive information and change settings via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Jan 2008
    6.4
    Medium

    CVE-2008-0473

    Last Modified: 23 Apr 2026

    RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.

    Published: 29 Jan 2008
    9.3
    Critical

    CVE-2008-0470

    Last Modified: 23 Apr 2026

    A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.

    Published: 29 Jan 2008
    10
    Critical

    CVE-2008-0467

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.

    Published: 29 Jan 2008
    Unknown

    CVE-2007-4576

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4575. Reason: This candidate is a reservation duplicate of CVE-2007-4575. Notes: All CVE users should reference CVE-2007-4575 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Jan 2008
    7.5
    High

    CVE-2008-0175

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory.

    Published: 29 Jan 2008
    10
    Critical

    CVE-2008-0176

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 29 Jan 2008
    7.8
    High

    CVE-2008-0387

    Last Modified: 23 Apr 2026

    Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

    Published: 29 Jan 2008
    9.8
    Critical

    CVE-2008-0174

    Last Modified: 23 Apr 2026

    GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.

    Published: 29 Jan 2008
    7.2
    High

    CVE-2008-0008

    Last Modified: 23 Apr 2026

    The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

    Published: 28 Jan 2008
    4.3
    Medium

    CVE-2008-0409

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.

    Published: 28 Jan 2008
    5
    Medium

    CVE-2008-0410

    Last Modified: 23 Apr 2026

    HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.

    Published: 28 Jan 2008
    6.4
    Medium

    CVE-2008-0408

    Last Modified: 23 Apr 2026

    HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.

    Published: 28 Jan 2008
    10
    Critical

    CVE-2008-0405

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.

    Published: 28 Jan 2008
    5
    Medium

    CVE-2008-0406

    Last Modified: 23 Apr 2026

    HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.

    Published: 28 Jan 2008
    5
    Medium

    CVE-2008-0407

    Last Modified: 23 Apr 2026

    HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.

    Published: 28 Jan 2008
    5
    Medium

    CVE-2008-0466

    Last Modified: 23 Apr 2026

    Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.

    Published: 28 Jan 2008
    7.5
    High

    CVE-2008-1568

    Last Modified: 23 Apr 2026

    comix 3.6.4 allows attackers to execute arbitrary commands via a filename containing shell metacharacters that are not properly sanitized when executing the rar, unrar, or jpegtran programs.

    Published: 27 Jan 2008
    4.3
    Medium

    CVE-2008-0460

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Jan 2008
    6.8
    Medium

    CVE-2008-0459

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.

    Published: 25 Jan 2008
    6.8
    Medium

    CVE-2008-0458

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php.

    Published: 25 Jan 2008
    5
    Medium

    CVE-2008-0465

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter.

    Published: 25 Jan 2008
    5
    Medium

    CVE-2008-0464

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Published: 25 Jan 2008
    4.3
    Medium

    CVE-2008-0463

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties.

    Published: 25 Jan 2008
    4.3
    Medium

    CVE-2008-0462

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Jan 2008
    6.8
    Medium

    CVE-2008-0461

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. NOTE: some of these details are obtained from third party information.

    Published: 25 Jan 2008
    7.2
    High

    CVE-2007-5764

    Last Modified: 23 Apr 2026

    Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.

    Published: 25 Jan 2008
    9.3
    Critical

    CVE-2008-0454

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

    Published: 25 Jan 2008
    4.3
    Medium

    CVE-2008-0455

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

    Published: 25 Jan 2008
    7.5
    High

    CVE-2008-0449

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in paypalresult.asp in VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Jan 2008
    5
    Medium

    CVE-2008-0445

    Last Modified: 23 Apr 2026

    The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information.

    Published: 24 Jan 2008
    6.8
    Medium

    CVE-2008-0453

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

    Published: 24 Jan 2008
    5
    Medium

    CVE-2008-0452

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a viewart action.

    Published: 24 Jan 2008
    7.5
    High

    CVE-2008-0446

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Jan 2008
    7.5
    High

    CVE-2008-0442

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Jan 2008
    7.5
    High

    CVE-2008-0451

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) siteadmin/article-edit.php; and unspecified parameters to (2) submitted-edit.php, (3) page-edit.php, (4) section-edit.php, (5) staff-edit.php, and (6) staff-access.php in siteadmin/.

    Published: 24 Jan 2008
    7.5
    High

    CVE-2008-0447

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter.

    Published: 24 Jan 2008
    7.5
    High

    CVE-2008-0448

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL in the libcurlemuinc parameter.

    Published: 24 Jan 2008
    7.5
    High

    CVE-2008-0450

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index.php, and the (2) DIR_LIBS parameter to (b) media.php and (c) xmlrpc/server.php in admin/.

    Published: 24 Jan 2008
    4.3
    Medium

    CVE-2008-0444

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.

    Published: 24 Jan 2008