CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-0443

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value. NOTE: some of these details are obtained from third party information.

    Published: 24 Jan 2008
    2.1
    Low

    CVE-2008-0441

    Last Modified: 23 Apr 2026

    IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive information.

    Published: 24 Jan 2008
    10
    Critical

    CVE-2008-0544

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the IMG_LoadLBM_RW function in IMG_lbm.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted IFF ILBM file. NOTE: some of these details are obtained from third party information.

    Published: 24 Jan 2008
    5
    Medium

    CVE-2008-0440

    Last Modified: 23 Apr 2026

    AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0428

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0438

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf.

    Published: 23 Jan 2008
    10
    Critical

    CVE-2008-0437

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0439

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0422

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Jan 2008
    6.8
    Medium

    CVE-2008-0423

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0424

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter.

    Published: 23 Jan 2008
    5
    Medium

    CVE-2008-0425

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0426

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) headline, or (3) text field in a message.

    Published: 23 Jan 2008
    7.8
    High

    CVE-2008-0427

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.

    Published: 23 Jan 2008
    5
    Medium

    CVE-2008-0431

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0432

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0433

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.

    Published: 23 Jan 2008
    9.3
    Critical

    CVE-2008-0434

    Last Modified: 23 Apr 2026

    Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.

    Published: 23 Jan 2008
    5
    Medium

    CVE-2008-0435

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0436

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0429

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.

    Published: 23 Jan 2008
    10
    Critical

    CVE-2007-6425

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.

    Published: 23 Jan 2008
    10
    Critical

    CVE-2008-0029

    Last Modified: 23 Apr 2026

    Cisco Application Velocity System (AVS) before 5.1.0 is installed with default passwords for some system accounts, which allows remote attackers to gain privileges.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0421

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.

    Published: 23 Jan 2008
    7.1
    High

    CVE-2008-0028

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet.

    Published: 23 Jan 2008
    5
    Medium

    CVE-2008-0395

    Last Modified: 23 Apr 2026

    Kayako SupportSuite 3.11.01 allows remote attackers to obtain server configuration information via a direct request to syncml/index.php, which prints the contents of the $_SERVER superglobal.

    Published: 23 Jan 2008
    10
    Critical

    CVE-2008-0401

    Last Modified: 23 Apr 2026

    Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.

    Published: 23 Jan 2008
    6
    Medium

    CVE-2008-0402

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

    Published: 23 Jan 2008
    5.5
    Medium

    CVE-2008-0403

    Last Modified: 23 Apr 2026

    The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0404

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "Most active bugs" summary.

    Published: 23 Jan 2008
    7.8
    High

    CVE-2008-0396

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.

    Published: 23 Jan 2008
    6.8
    Medium

    CVE-2008-0399

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0400

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0398

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0394

    Last Modified: 23 Apr 2026

    Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.

    Published: 23 Jan 2008
    6.8
    Medium

    CVE-2008-0397

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.

    Published: 23 Jan 2008
    5.8
    Medium

    CVE-2008-0393

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.

    Published: 23 Jan 2008
    9.3
    Critical

    CVE-2008-0392

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.

    Published: 23 Jan 2008
    6.8
    Medium

    CVE-2008-0388

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI.

    Published: 23 Jan 2008
    10
    Critical

    CVE-2008-0389

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0390

    Last Modified: 23 Apr 2026

    stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-0391

    Last Modified: 23 Apr 2026

    inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2008-7220

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.

    Published: 23 Jan 2008
    7.5
    High

    CVE-2007-6697

    Last Modified: 23 Apr 2026

    Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, a similar issue to CVE-2006-4484. NOTE: some of these details are obtained from third party information.

    Published: 23 Jan 2008
    4.3
    Medium

    CVE-2008-0370

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dohtaccess.html in cPanel before 11.17 build 19417 allows remote attackers to inject arbitrary web script or HTML via the rurl parameter. NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2008
    6.8
    Medium

    CVE-2008-0371

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc/receivertwo.php; and allow remote attackers to execute arbitrary SQL commands via (2) the id parameter to (b) inc/usercp.php, related to functionz/usercp.php; or (3) the username parameter to (c) admin/index.php, related to functionz/first_process.php, or (d) index.php. NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2008
    5
    Medium

    CVE-2008-0372

    Last Modified: 23 Apr 2026

    8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP request.

    Published: 22 Jan 2008
    10
    Critical

    CVE-2008-0377

    Last Modified: 23 Apr 2026

    MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.

    Published: 22 Jan 2008
    10
    Critical

    CVE-2008-0380

    Last Modified: 23 Apr 2026

    Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

    Published: 22 Jan 2008