CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2008-0199

    Last Modified: 23 Apr 2026

    PRO-Search 0.17 and earlier allows remote attackers to cause a denial of service via certain values of the show_page and time parameters to the default URI.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0202

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0205

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.

    Published: 10 Jan 2008
    5.8
    Medium

    CVE-2008-0209

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0208

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2007-6677

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.

    Published: 10 Jan 2008
    5
    Medium

    CVE-2008-0191

    Last Modified: 23 Apr 2026

    WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0204

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to wp-admin/options-general.php.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0206

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) captcha_ttffolder, (2) captcha_numchars, (3) captcha_ttfrange, or (4) captcha_secret parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0207

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.

    Published: 10 Jan 2008
    5
    Medium

    CVE-2008-0195

    Last Modified: 23 Apr 2026

    WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.

    Published: 10 Jan 2008
    5.8
    Medium

    CVE-2007-6018

    Last Modified: 23 Apr 2026

    IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, which allows remote attackers to (1) delete arbitrary e-mail messages via a modified numeric ID or (2) "purge" deleted emails via a crafted email message.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0192

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.

    Published: 10 Jan 2008
    5
    Medium

    CVE-2008-0196

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the page parameter to certain PHP scripts under wp-admin/ or (2) the import parameter to wp-admin/admin.php, as demonstrated by discovering the full path via a request for the \..\..\wp-config pathname; and allow remote attackers to modify arbitrary files via a .. (dot dot) in the file parameter to wp-admin/templates.php.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0201

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0203

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cryptwidth, (2) cryptheight, (3) bgimg, (4) charR, (5) charG, (6) charB, (7) charclear, (8) tfont, (9) charel, (10) charelc, (11) charelv, (12) charnbmin, (13) charnbmax, (14) charspace, (15) charsizemin, (16) charsizemax, (17) charanglemax, (18) noisepxmin, (19) noisepxmax, (20) noiselinemin, (21) noiselinemax, (22) nbcirclemin, (23) nbcirclemax, or (24) brushsize parameter to wp-admin/options-general.php.

    Published: 10 Jan 2008
    6.4
    Medium

    CVE-2008-0210

    Last Modified: 23 Apr 2026

    Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.

    Published: 10 Jan 2008
    8.8
    High

    CVE-2008-0127

    Last Modified: 23 Apr 2026

    The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0190

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0193

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0194

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrary files, and cause a denial of service via a .. (dot dot) in the backup parameter in a wp-db-backup.php action to wp-admin/edit.php. NOTE: this might be the same as CVE-2006-5705.1.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0200

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter.

    Published: 10 Jan 2008
    9.3
    Critical

    CVE-2007-6250

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow remote attackers to execute arbitrary code via the AppendFileToPlayList method.

    Published: 9 Jan 2008
    10
    Critical

    CVE-2007-6532

    Last Modified: 23 Apr 2026

    Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend id, program name and working directory in session management."

    Published: 9 Jan 2008
    5
    Medium

    CVE-2007-6531

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via Launcher tooltips. NOTE: a second buffer overflow (over-read) in the xfce_mkdirhier function was also reported, but it might not be exploitable for a crash or code execution, so it is not a vulnerability.

    Published: 9 Jan 2008
    6.4
    Medium

    CVE-2008-0184

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.

    Published: 9 Jan 2008
    7.5
    High

    CVE-2008-0185

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).

    Published: 9 Jan 2008
    4.3
    Medium

    CVE-2008-0186

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.

    Published: 9 Jan 2008
    7.5
    High

    CVE-2008-0187

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.

    Published: 9 Jan 2008
    7.2
    High

    CVE-2007-5762

    Last Modified: 23 Apr 2026

    NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.

    Published: 9 Jan 2008
    6.5
    Medium

    CVE-2007-5401

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files, related to not properly checking file extensions.

    Published: 9 Jan 2008
    3.5
    Low

    CVE-2007-5403

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax fields to writeenduserenduser.asp; the (5) Filter field to statsrequestypereport.asp; and the (6) sys_request_id parameter to requestattach.asp; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) Asset, (8) Location, and (9) Problem fields to editrequestenduser.asp; the (10) Asset, (11) Asset Location, (12) Problem Desc, and (13) Solution Desc fields to editrequestuser.asp; and the (14) End User and (15) Description fields to usersearchrequests.asp. NOTE: vectors 5 and 6 do not require authentication to exploit.

    Published: 9 Jan 2008
    7.2
    High

    CVE-2007-5616

    Last Modified: 23 Apr 2026

    ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges via unspecified vectors.

    Published: 9 Jan 2008
    5
    Medium

    CVE-2007-5404

    Last Modified: 23 Apr 2026

    Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames.

    Published: 9 Jan 2008
    6.5
    Medium

    CVE-2007-5402

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp; and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp, and the sys_request_id parameter to (3) changerequeststatus.asp, (4) editrequestuser.asp, (5) requestcommentsuser.asp, and (6) useractions.asp, different vectors than CVE-2004-2551.

    Published: 9 Jan 2008
    4.3
    Medium

    CVE-2008-0152

    Last Modified: 23 Apr 2026

    SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference. NOTE: the crash is not user-assisted when the server is running in debug mode.

    Published: 9 Jan 2008
    7.2
    High

    CVE-2007-5761

    Last Modified: 23 Apr 2026

    The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the SYSENTER_EIP_MSR CPU Model Specific Register (MSR) value.

    Published: 9 Jan 2008
    7.5
    High

    CVE-2008-0238

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3) Copyright attribute, related to the rmff_dump_header function, different vectors than CVE-2008-0225. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Jan 2008
    7.5
    High

    CVE-2008-0154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.

    Published: 9 Jan 2008
    5
    Medium

    CVE-2008-0153

    Last Modified: 23 Apr 2026

    telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference.

    Published: 9 Jan 2008
    7.2
    High

    CVE-2007-5665

    Last Modified: 23 Apr 2026

    STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts in a world-writable directory when generating diagnostic reports, which allows local users to gain privileges, as demonstrated by creating a cmd.exe binary in the diagnostic report directory.

    Published: 9 Jan 2008
    6.8
    Medium

    CVE-2008-0147

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.

    Published: 9 Jan 2008
    10
    Critical

    CVE-2008-0148

    Last Modified: 23 Apr 2026

    TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.

    Published: 9 Jan 2008
    5
    Medium

    CVE-2008-0149

    Last Modified: 23 Apr 2026

    TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.

    Published: 9 Jan 2008
    6.8
    Medium

    CVE-2008-0150

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access.

    Published: 9 Jan 2008
    10
    Critical

    CVE-2008-0151

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options.

    Published: 9 Jan 2008
    4.3
    Medium

    CVE-2008-0155

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.

    Published: 9 Jan 2008
    5
    Medium

    CVE-2008-0156

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in index.php in Million Dollar Script 2.0.14 allows remote attackers to read arbitrary files via encoded "/" (%2F) sequences in the link parameter.

    Published: 9 Jan 2008
    7.5
    High

    CVE-2008-0157

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.

    Published: 9 Jan 2008
    5
    Medium

    CVE-2008-0158

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.

    Published: 9 Jan 2008