10
    Critical

    CVE-2008-7010

    Last Modified: 22 Dec 2016

    Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.

    Source:mr.al7rbi
    Published:19 Aug 2009
    6.9
    Medium

    CVE-2008-7009

    Last Modified: 19 Mar 2014

    Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.

    Source:Juan Pablo Lopez Yacubian
    Published:19 Aug 2009
    5
    Medium

    CVE-2008-7008

    Last Modified: 20 Mar 2014

    HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.

    Source:r45c4l
    Published:19 Aug 2009
    7.5
    High

    CVE-2008-7007

    Last Modified: 23 Apr 2026

    Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.

    Source:Stack
    Published:19 Aug 2009
    5
    Medium

    CVE-2008-7006

    Last Modified: 23 Apr 2026

    Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.

    Source:SirGod
    Published:19 Aug 2009
    7.5
    High

    CVE-2008-7005

    Last Modified: 23 Dec 2016

    include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edit parameter. NOTE: this issue has been reported as an unrestricted file upload by some sources, but that is a potential consequence of code execution.

    Source:Khashayar Fereidani
    Published:19 Aug 2009
    7.5
    High

    CVE-2008-7003

    Last Modified: 6 Jan 2017

    Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary SQL commands via the (1) user_id and (2) password parameter.

    Source:x0r
    Published:18 Aug 2009
    7.2
    High

    CVE-2008-7002

    Last Modified: 18 Mar 2014

    PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

    Source:Ciph3r
    Published:9 Sept 2008
    7.5
    High

    CVE-2008-7001

    Last Modified: 21 Dec 2016

    Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors.

    Source:ThE X-HaCkEr
    Published:18 Aug 2009
    7.5
    High

    CVE-2008-7000

    Last Modified: 6 May 2014

    PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.

    Source:Beenu Arora
    Published:18 Aug 2009
    9.3
    Critical

    CVE-2008-6998

    Last Modified: 30 Oct 2016

    Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.

    Source:Shinnok
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2008-6997

    Last Modified: 30 Oct 2016

    Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action.

    Source:Metacortex
    Published:18 Aug 2009
    5
    Medium

    CVE-2008-6996

    Last Modified: 30 Oct 2016

    Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.

    Source:nerex
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2008-6995

    Last Modified: 30 Oct 2016

    Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.

    Source:Rishi Narang
    Published:18 Aug 2009
    9.3
    Critical

    CVE-2008-6994

    Last Modified: 30 Oct 2016

    Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated. NOTE: it might be possible to exploit this issue via an HTTP response that includes a long filename in a Content-Disposition header.

    Source:SVRT
    Published:18 Aug 2009
    7.5
    High

    CVE-2008-6992

    Last Modified: 6 May 2014

    GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.

    Source:Johannes Dahse
    Published:18 Aug 2009
    7.5
    High

    CVE-2008-6991

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL commands via the id_rub_page parameter.

    Source:h4ck3r
    Published:18 Aug 2009
    7.5
    High

    CVE-2008-6990

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Khashayar Fereidani
    Published:18 Aug 2009
    7.5
    High

    CVE-2008-6989

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Khashayar Fereidani
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2008-6988

    Last Modified: 23 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) galleryid parameter to gallery.php, and the (2) size or (3) imageid parameters to show.php.

    Source:Khashayar Fereidani
    Published:18 Aug 2009
    6.8
    Medium

    CVE-2008-6985

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.

    Source:GulfTech Security
    Published:18 Aug 2009
    7.5
    High

    CVE-2008-6983

    Last Modified: 7 Dec 2016

    modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.

    Source:Khashayar Fereidani
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2008-6982

    Last Modified: 7 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.

    Source:Khashayar Fereidani
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2008-6979

    Last Modified: 18 Mar 2014

    Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant from a separate SQL injection vulnerability.

    Source:David Sopas
    Published:18 Aug 2009
    6.8
    Medium

    CVE-2008-6978

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp.

    Source:e.wiZz!
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2008-6977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action.

    Source:e.wiZz!
    Published:18 Aug 2009
    6.4
    Medium

    CVE-2008-6976

    Last Modified: 13 Mar 2018

    MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.

    Source:ShadOS
    Published:18 Aug 2009
    6.8
    Medium

    CVE-2008-6975

    Last Modified: 27 Oct 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters. NOTE: This issue reportedly exists because of a "weak ... anti-CSRF fix" implemented in 24 sp2.

    Source:gat3way
    Published:14 Aug 2009
    6.8
    Medium

    CVE-2008-6974

    Last Modified: 27 Oct 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters.

    Source:gat3way
    Published:14 Aug 2009
    7.5
    High

    CVE-2008-6971

    Last Modified: 9 Dec 2016

    The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.

    Source:Raz0r
    Published:13 Aug 2009
    7.5
    High

    CVE-2008-6970

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.

    Source:GulfTech Security
    Published:13 Aug 2009
    7.5
    High

    CVE-2008-6968

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.

    Source:GulfTech Security
    Published:13 Aug 2009
    7.5
    High

    CVE-2008-6966

    Last Modified: 23 Apr 2026

    AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php.

    Source:G4N0K
    Published:13 Aug 2009
    7.5
    High

    CVE-2008-6965

    Last Modified: 23 Apr 2026

    AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors.

    Source:G4N0K
    Published:13 Aug 2009
    7.5
    High

    CVE-2008-6964

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands via the password field.

    Source:ZoRLu
    Published:13 Aug 2009
    7.5
    High

    CVE-2008-6963

    Last Modified: 23 Apr 2026

    admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request.

    Source:G4N0K
    Published:13 Aug 2009
    5
    Medium

    CVE-2008-6960

    Last Modified: 23 Apr 2026

    download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitrary files via an encoded url parameter, as demonstrated by obtaining database credentials from includes/constants.php.

    Source:THUNDER
    Published:12 Aug 2009
    9.3
    Critical

    CVE-2008-6959

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attackers to overwrite arbitrary files via the SaveLastError method. NOTE: this might be related to CVE-2008-1647.

    Source:Zigma
    Published:12 Aug 2009
    6.5
    Medium

    CVE-2008-6958

    Last Modified: 23 Apr 2026

    wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter.

    Source:80vul
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6957

    Last Modified: 23 Apr 2026

    member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.

    Source:80vul
    Published:12 Aug 2009
    6.5
    Medium

    CVE-2008-6956

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.

    Source:ahmadbady
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6955

    Last Modified: 23 Apr 2026

    mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini.

    Source:ahmadbady
    Published:12 Aug 2009
    9.3
    Critical

    CVE-2008-6953

    Last Modified: 23 Apr 2026

    Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long oovoo: URI.

    Source:Nine:Situations:Group
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6952

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:StAkeR
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6950

    Last Modified: 2 Jan 2017

    Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

    Source:R3d-D3V!L
    Published:12 Aug 2009
    6.8
    Medium

    CVE-2008-6949

    Last Modified: 6 Jan 2017

    Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the authentication of administrators for requests that (1) submit or edit a new project, or (2) upload files to a project, or (3) attach files to messages via unknown vectors. NOTE: these issues can be leveraged with other vulnerabilities to create remote attack vectors that do not require authentication.

    Source:USH
    Published:12 Aug 2009
    6.5
    Medium

    CVE-2008-6948

    Last Modified: 6 Jan 2017

    Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and using a text/plain MIME type, then accessing it via a direct request to the file in files/, related to (1) the showproject action in managefile.php or (2) the Messages feature.

    Source:USH
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6947

    Last Modified: 6 Jan 2017

    Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via unspecified vectors associated with the added mode in a users action to admin.php.

    Source:USH
    Published:12 Aug 2009
    4.3
    Medium

    CVE-2008-6946

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via the project Name, which is not properly handled when the administrator performs an editform action, related to admin.php.

    Source:USH
    Published:12 Aug 2009
    6.5
    Medium

    CVE-2008-6944

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/.

    Source:ZoRLu
    Published:12 Aug 2009