9.3
    Critical

    CVE-2008-7074

    Last Modified: 27 Nov 2017

    Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a server response, which is not properly handled "when displaying the signon message."

    Source:Alfons Luja
    Published:25 Aug 2009
    6.8
    Medium

    CVE-2008-7073

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lib parameter.

    Source:ZoRLu
    Published:25 Aug 2009
    4.3
    Medium

    CVE-2008-7072

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML via the start parameter.

    Source:ZoRLu
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7071

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:25 Aug 2009
    9.3
    Critical

    CVE-2008-7070

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI. NOTE: this might be due to an incomplete fix for CVE-2007-2951.

    Source:Nine:Situations:Group
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7069

    Last Modified: 6 Jan 2017

    All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat.

    Source:StAkeR
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7067

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[PT_Config][dir][data] parameter.

    Source:NoGe
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7066

    Last Modified: 23 Apr 2026

    OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters.

    Source:CWH Underground
    Published:25 Aug 2009
    7.8
    High

    CVE-2008-7065

    Last Modified: 23 Apr 2026

    Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP packet to UDP port 5060.

    Source:sky & Any
    Published:25 Aug 2009
    7.5
    High

    CVE-2008-7064

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for "/" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.

    Source:girex
    Published:25 Aug 2009
    5
    Medium

    CVE-2008-7063

    Last Modified: 23 Apr 2026

    Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for admin/o12faq.mdb.

    Source:Stack
    Published:25 Aug 2009
    6.8
    Medium

    CVE-2008-7062

    Last Modified: 26 Dec 2010

    Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

    Source:cOndemned
    Published:25 Aug 2009
    4.3
    Medium

    CVE-2008-7061

    Last Modified: 17 Mar 2014

    The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title attribute, which is not properly handled when displaying a tooltip, a different vulnerability than CVE-2008-6994. NOTE: there is inconsistent information about the environments under which this issue exists.

    Source:Exodus
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7059

    Last Modified: 16 Mar 2014

    SQL injection vulnerability in index.php in One-News Beta 2 allows remote attackers to execute arbitrary SQL commands via the q parameter.

    Source:suN8Hclf
    Published:24 Aug 2009
    6.8
    Medium

    CVE-2008-7058

    Last Modified: 21 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and force a logout via adminpanel/logout.php.

    Source:SirGod
    Published:24 Aug 2009
    4.3
    Medium

    CVE-2008-7057

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web script via the type parameter.

    Source:SirGod
    Published:24 Aug 2009
    5
    Medium

    CVE-2008-7056

    Last Modified: 21 Dec 2016

    BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request.

    Source:SirGod
    Published:24 Aug 2009
    5.1
    Medium

    CVE-2008-7055

    Last Modified: 23 Apr 2026

    module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include and execute arbitrary local files via "....//" (doubled dot dot slash) sequences in the link parameter, which is not properly filtered using the str_replace function.

    Source:DSecRG
    Published:24 Aug 2009
    5.1
    Medium

    CVE-2008-7054

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary local files via the (1) gsLanguage and (2) language_home parameters to modules/diary/showdiary.php; (3) admin_home, (4) gsLanguage, and (5) language_home parameters to modules/diary/showdiarydetail.php; (6) gsLanguage and (7) language_home parameters to modules/diary/submit_diary.php; (8) admin_home parameter to modules/news/news_summary.php; (9) nLink, (10) gsLanguage, and (11) language_home parameters to modules/news/inlinenews.php; and possibly other unspecified vectors in (12) diary/showeventlist.php, (13) gallery/showgallery.php, (14) reviews/showreviews.php, (15) gallery/showgallerydetails.php, (16) reviews/showreviewsdetails.php, (17) news/shownewsdetails.php, (18) gallery/submit_gallery.php, (19) guestbook/submit_guestbook.php, (20) reviews/submit_reviews.php, (21) news/submit_news.php, (22) diary/inlineeventlist.php, and (23) news/archivednews_summary.php in modules/, related to the lack of directory traversal protection in modules/moduleSec.php.

    Source:DSecRG
    Published:24 Aug 2009
    9.3
    Critical

    CVE-2008-7053

    Last Modified: 23 Apr 2026

    LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption.

    Source:YAG KOHHA
    Published:24 Aug 2009
    6.5
    Medium

    CVE-2008-7052

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.

    Source:BackDoor
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7051

    Last Modified: 28 Nov 2016

    AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.

    Source:G4N0K
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7049

    Last Modified: 3 Jan 2017

    Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitrary SQL commands via the (1) txtUsername parameter (aka Username) and (2) txtPassword parameter (aka Password) in a form generated by home.asp. NOTE: due to lack of details, it is not clear whether this is related to CVE-2004-2206.

    Source:Bl@ckbe@rD
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7047

    Last Modified: 23 Apr 2026

    NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct request to admin/home.asp.

    Source:Stack
    Published:24 Aug 2009
    6.4
    Medium

    CVE-2008-7046

    Last Modified: 23 Apr 2026

    AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:G4N0K
    Published:24 Aug 2009
    6.4
    Medium

    CVE-2008-7045

    Last Modified: 23 Apr 2026

    AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.

    Source:G4N0K
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7044

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.

    Source:G4N0K
    Published:24 Aug 2009
    4.3
    Medium

    CVE-2008-7043

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter. NOTE: this can be leveraged to modify cookies and conduct session fixation attacks.

    Source:Don
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7042

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter.

    Source:Don
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7041

    Last Modified: 23 Apr 2026

    AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.

    Source:G4N0K
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7040

    Last Modified: 28 Jan 2014

    SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

    Source:S@BUN
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7038

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the gid parameter in a showgall action to modules.php. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

    Source:Aria-Security Team
    Published:24 Aug 2009
    4.3
    Medium

    CVE-2008-7036

    Last Modified: 21 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.

    Source:Lostmon
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7033

    Last Modified: 30 Jan 2014

    SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the section parameter in a section action to index.php, a different vulnerability than CVE-2008-2568. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.

    Source:S@BUN
    Published:24 Aug 2009
    6.8
    Medium

    CVE-2008-7032

    Last Modified: 22 Jan 2014

    Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of administrators for requests that create new administrators and execute shell commands, as demonstrated using tmui/Control/form.

    Source:nnposter
    Published:24 Aug 2009
    10
    Critical

    CVE-2008-7031

    Last Modified: 28 Jan 2014

    Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151.

    Source:Luigi Auriemma
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7030

    Last Modified: 26 Jan 2014

    Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

    Source:S@BUN
    Published:24 Aug 2009
    7.5
    High

    CVE-2008-7028

    Last Modified: 23 Apr 2026

    RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.

    Source:Stack
    Published:21 Aug 2009
    7.5
    High

    CVE-2008-7027

    Last Modified: 23 Dec 2016

    Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.

    Source:Stack
    Published:21 Aug 2009
    6.8
    Medium

    CVE-2008-7026

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.

    Source:Pepelux
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2008-7025

    Last Modified: 21 Mar 2014

    TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.

    Source:quakerdoomer
    Published:21 Aug 2009
    6.8
    Medium

    CVE-2008-7024

    Last Modified: 23 Apr 2026

    admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."

    Source:Pepelux
    Published:21 Aug 2009
    9.3
    Critical

    CVE-2008-7022

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method.

    Source:e.wiZz!
    Published:21 Aug 2009
    6
    Medium

    CVE-2008-7021

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory.

    Source:InjEctOr5
    Published:21 Aug 2009
    7.5
    High

    CVE-2008-7019

    Last Modified: 23 Apr 2026

    Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.

    Source:ZoRLu
    Published:21 Aug 2009
    4.3
    Medium

    CVE-2008-7017

    Last Modified: 23 Mar 2014

    Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate.

    Source:Alexander Klink
    Published:21 Aug 2009
    5
    Medium

    CVE-2008-7015

    Last Modified: 19 Mar 2014

    Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.

    Source:Luigi Auriemma
    Published:19 Aug 2009
    5
    Medium

    CVE-2008-7014

    Last Modified: 23 Apr 2026

    fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value.

    Source:Jeremy Brown
    Published:19 Aug 2009
    7.8
    High

    CVE-2008-7012

    Last Modified: 20 Mar 2014

    courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.

    Source:Eric Beaulieu
    Published:19 Aug 2009
    4
    Medium

    CVE-2008-7011

    Last Modified: 21 Mar 2014

    The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.

    Source:Luigi Auriemma
    Published:19 Aug 2009