7.5
    High

    CVE-2008-7167

    Last Modified: 9 Dec 2016

    Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Source:CWH Underground
    Published:8 Sept 2009
    6.8
    Medium

    CVE-2008-7165

    Last Modified: 20 Jan 2014

    Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi allows remote attackers to hijack the authentication of administrators for requests that disable Wi-Fi encryption via certain values for the wlChannel and wlRadioEnable parameters.

    Source:WarGame
    Published:4 Sept 2009
    6.8
    Medium

    CVE-2008-7163

    Last Modified: 8 Nov 2016

    Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the sine[config][index_main] parameter.

    Source:KiNgOfThEwOrLd
    Published:4 Sept 2009
    9.3
    Critical

    CVE-2008-7162

    Last Modified: 23 Apr 2026

    Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.

    Source:fl0 fl0w
    Published:4 Sept 2009
    7.5
    High

    CVE-2008-7161

    Last Modified: 19 Jan 2014

    Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST requests that use HTTP/1.0 without the Host header. NOTE: this issue might be related to CVE-2005-3058.

    Source:Danux
    Published:4 Sept 2009
    6.8
    Medium

    CVE-2008-7157

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in uploaded/avatars/.

    Source:Eugene Minaev
    Published:2 Sept 2009
    6.8
    Medium

    CVE-2008-7156

    Last Modified: 23 Apr 2026

    EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.

    Source:Eugene Minaev
    Published:2 Sept 2009
    7.5
    High

    CVE-2008-7155

    Last Modified: 30 Dec 2016

    NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users via a direct request.

    Source:Cod3rZ
    Published:2 Sept 2009
    5
    Medium

    CVE-2008-7154

    Last Modified: 23 Apr 2026

    Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/class.conf_fw.php, (2) class.module/class.event_manager.php, (3) lib/lib.domxml5.php, or (4) menu/menu_over.php in doceboCore/; or (5) class/class.conf_cms.php, (6) lib/lib.compose.php, (7) modules/chat/teleskill.php, or (8) class/class.admin_menu_cms.php in doceboCms/; which reveals the installation path in an error message.

    Source:EgiX
    Published:2 Sept 2009
    7.5
    High

    CVE-2008-7153

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Accept-Language HTTP header. NOTE: this can be leveraged to execute arbitrary PHP code using the INTO DUMPFILE command.

    Source:rgod
    Published:2 Sept 2009
    6.8
    Medium

    CVE-2008-7152

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php.

    Source:Kw3[R]Ln
    Published:1 Sept 2009
    7.5
    High

    CVE-2008-7145

    Last Modified: 10 Feb 2014

    Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters.

    Source:Virangar Security
    Published:1 Sept 2009
    5
    Medium

    CVE-2008-7142

    Last Modified: 6 Feb 2014

    Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arbitrary directories via the showtree parameter.

    Source:Linux_Drox
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2008-7141

    Last Modified: 11 Feb 2014

    Cross-site scripting (XSS) vulnerability in setup.php in @lex Poll 2.1 allows remote attackers to inject arbitrary web script or HTML via the language_setup parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2008-7140

    Last Modified: 11 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: a third party has been reported that the test parameter is not used in @lex Guestbook.

    Source:ZoRLu
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2008-7136

    Last Modified: 23 Apr 2026

    toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyById method, different vectors than CVE-2008-7135.

    Source:spdr
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2008-7135

    Last Modified: 23 Apr 2026

    toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector than CVE-2008-7136.

    Source:spdr
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2008-7134

    Last Modified: 4 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the default URI in Chris LaPointe RedGalaxy Download Center 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter, (2) message parameter in a login action, (3) category parameter in a browse action, (4) now parameter, or (5) search parameter in a search_results action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2008-7133

    Last Modified: 3 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in onlinetools.org EasyImageCatalogue 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search and (2) d index.php parameters to index.php, (3) dir parameter to thumber.php, and the d parameter to (4) describe.php and (5) addcomment.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:1 Sept 2009
    10
    Critical

    CVE-2008-7126

    Last Modified: 5 Feb 2014

    Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet with a large string length value to UDP port 14000, which triggers a heap-based buffer overflow.

    Source:Luigi Auriemma
    Published:31 Aug 2009
    7.5
    High

    CVE-2008-7124

    Last Modified: 23 Apr 2026

    zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.

    Source:Charles Fol
    Published:31 Aug 2009
    6.8
    Medium

    CVE-2008-7123

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php via a null byte (%00) in the login parameter in an ajout action, which bypasses the regular expression check.

    Source:Charles Fol
    Published:31 Aug 2009
    7.5
    High

    CVE-2008-7120

    Last Modified: 19 Mar 2014

    SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter.

    Source:r45c4l
    Published:28 Aug 2009
    7.5
    High

    CVE-2008-7119

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Stack
    Published:28 Aug 2009
    5
    Medium

    CVE-2008-7118

    Last Modified: 21 Dec 2016

    WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.

    Source:InjEctOr5
    Published:28 Aug 2009
    5
    Medium

    CVE-2008-7117

    Last Modified: 21 Dec 2016

    eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be leveraged for cross-site scripting (XSS) attacks.

    Source:InjEctOr5
    Published:28 Aug 2009
    7.5
    High

    CVE-2008-7116

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.

    Source:InjEctOr5
    Published:28 Aug 2009
    10
    Critical

    CVE-2008-7115

    Last Modified: 8 Sept 2017

    The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/. NOTE: the setup_dns.exe vector is already covered by CVE-2008-1244.

    Source:noensr
    Published:28 Aug 2009
    6.8
    Medium

    CVE-2008-7114

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the name field.

    Source:~!Dok_tOR!~
    Published:28 Aug 2009
    7.8
    High

    CVE-2008-7110

    Last Modified: 17 Mar 2014

    Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request.

    Source:Seth Fogie
    Published:28 Aug 2009
    7.2
    High

    CVE-2008-7107

    Last Modified: 23 Apr 2026

    easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request to the \\.\easdrv device interface.

    Source:g_
    Published:28 Aug 2009
    9.3
    Critical

    CVE-2008-7103

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of service (browser crash) or execute arbitrary code via a long Document.Location property value.

    Source:shinnai
    Published:27 Aug 2009
    6.8
    Medium

    CVE-2008-7099

    Last Modified: 20 Dec 2016

    Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Corwin
    Published:27 Aug 2009
    4.3
    Medium

    CVE-2008-7098

    Last Modified: 20 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3) the gallery, possibly the Description field in Your Pictures; (4) the forum, possibly the Your Message field when posting a new thread; or (5) the vote parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.

    Source:Corwin
    Published:27 Aug 2009
    7.5
    High

    CVE-2008-7097

    Last Modified: 20 Dec 2016

    Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php.

    Source:Corwin
    Published:27 Aug 2009
    7.5
    High

    CVE-2008-7091

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/link.php; (2) id parameter to trackback.php; (3) an unspecified parameter to submit.php; (4) requestTitle variable in a query to story.php; (5) requestID and (6) requestTitle variables in recommend.php; (7) categoryID parameter to cloud.php; (8) title parameter to out.php; (9) username parameter to login.php; (10) id parameter to cvote.php; and (11) commentid parameter to edit.php.

    Source:GulfTech Security
    Published:26 Aug 2009
    7.8
    High

    CVE-2008-7090

    Last Modified: 5 Jan 2018

    Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url variable in trackback.php, or (2) include arbitrary files via a .. (dot dot) in the template parameter to settemplate.php.

    Source:GulfTech Security
    Published:26 Aug 2009
    4.3
    Medium

    CVE-2008-7089

    Last Modified: 5 Jan 2018

    Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other unspecified vectors.

    Source:GulfTech Security
    Published:26 Aug 2009
    6.5
    Medium

    CVE-2008-7088

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in a certain path. NOTE: this may be the same vulnerability as CVE-2008-0251, but this is not clear due to lack of details from the vendor.

    Source:Cold Zero
    Published:26 Aug 2009
    7.5
    High

    CVE-2008-7087

    Last Modified: 5 Mar 2014

    PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBPATH parameter.

    Source:Ghost Hacker
    Published:26 Aug 2009
    7.5
    High

    CVE-2008-7086

    Last Modified: 23 Apr 2026

    Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.

    Source:Saime
    Published:26 Aug 2009
    7.5
    High

    CVE-2008-7085

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2) divid parameter in the schedule action to index.php.

    Source:Mr.SQL
    Published:26 Aug 2009
    5
    Medium

    CVE-2008-7084

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:DSecRG
    Published:26 Aug 2009
    7.5
    High

    CVE-2008-7083

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Source:R3d-D3V!L
    Published:25 Aug 2009
    5
    Medium

    CVE-2008-7080

    Last Modified: 23 Apr 2026

    Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

    Source:InjEctOr5
    Published:25 Aug 2009
    9.3
    Critical

    CVE-2008-7079

    Last Modified: 23 Apr 2026

    Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a .M3U playlist file. NOTE: this issue might be related to CVE-2008-0619.

    Source:LiquidWorm
    Published:25 Aug 2009
    9
    Critical

    CVE-2008-7078

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow remote authenticated users to execute arbitrary code via a long argument to the (2) MKD, (3) XMKD, (4) RMD, and other unspecified commands in the FTP component.

    Source:BLUE MOON
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7077

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in SailPlanner 0.3a allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Source:JIKO
    Published:25 Aug 2009
    6.5
    Medium

    CVE-2008-7076

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/.

    Source:ZoRLu
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7075

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5) article.download.php; and (6) the PATH_INFO to article.download.php. NOTE: some of these details are obtained from third party information.

    Source:b3hz4d
    Published:25 Aug 2009