6.5
    Medium

    CVE-2008-6943

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.

    Source:ZoRLu
    Published:12 Aug 2009
    6.5
    Medium

    CVE-2008-6942

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.

    Source:ZoRLu
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6941

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to execute arbitrary SQL commands via the password field.

    Source:G4N0K
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6940

    Last Modified: 23 Apr 2026

    TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a database backup via a direct request to admin/backup/db.

    Source:G4N0K
    Published:12 Aug 2009
    7.5
    High

    CVE-2008-6939

    Last Modified: 23 Apr 2026

    TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username.

    Source:G4N0K
    Published:12 Aug 2009
    4.3
    Medium

    CVE-2008-6938

    Last Modified: 23 Apr 2026

    Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.

    Source:Hamid Ebadi
    Published:11 Aug 2009
    10
    Critical

    CVE-2008-6937

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Nine:Situations:Group
    Published:11 Aug 2009
    9.3
    Critical

    CVE-2008-6936

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.

    Source:Nine:Situations:Group
    Published:11 Aug 2009
    10
    Critical

    CVE-2008-6935

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.

    Source:Nine:Situations:Group
    Published:11 Aug 2009
    7.5
    High

    CVE-2008-6934

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some of these details are obtained from third party information.

    Source:GoLd_M
    Published:11 Aug 2009
    5
    Medium

    CVE-2008-6933

    Last Modified: 2 Jan 2017

    Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via a .. (dot dot) in the list parameter.

    Source:Alfons Luja
    Published:11 Aug 2009
    7.5
    High

    CVE-2008-6932

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in send/files/.

    Source:ZoRLu
    Published:11 Aug 2009
    6.5
    Medium

    CVE-2008-6931

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a resume photo, then accessing it via a direct request to the file in jobseekers/jobseeker_profile_images.

    Source:ZoRLu
    Published:11 Aug 2009
    6.5
    Medium

    CVE-2008-6930

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/.

    Source:ZoRLu
    Published:11 Aug 2009
    6.5
    Medium

    CVE-2008-6929

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/.

    Source:ZoRLu
    Published:11 Aug 2009
    6.5
    Medium

    CVE-2008-6928

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/.

    Source:ZoRLu
    Published:11 Aug 2009
    4.3
    Medium

    CVE-2008-6927

    Last Modified: 30 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5) thispage, (6) thisapp, and (7) currentversion parameters in an Upgrade action.

    Source:Khashayar Fereidani
    Published:10 Aug 2009
    6.8
    Medium

    CVE-2008-6926

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.

    Source:Khashayar Fereidani
    Published:10 Aug 2009
    4.3
    Medium

    CVE-2008-6924

    Last Modified: 4 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in eSyndiCat Directory 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) email, (3) password, (4) password2, (5) security_code, and (6) register parameters.

    Source:Fugitif
    Published:10 Aug 2009
    7.5
    High

    CVE-2008-6923

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.

    Source:unknown_styler
    Published:10 Aug 2009
    9.3
    Critical

    CVE-2008-6922

    Last Modified: 13 Dec 2016

    Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary code via a long argument to the (1) CreateUserPath, (2) Logout, (3) DeleteMailByUID, (4) MoveToInbox, (5) MoveToFolder, (6) DeleteMailEx, (7) GetMailDataEx, (8) SetReplySign, (9) SetForwardSign, and (10) SetReadSign methods, which are not properly handled by (a) the POP3 Class ActiveX control (CMailCom.POP3); or a long argument to the (11) AddAttach, (12) SetSubject, (13) SetBcc, (14) SetBody, (15) SetCc, (16) SetFrom, (17) SetTo, and (18) SetFromUID methods, which are not properly handled by the Class ActiveX control (CMailCOM.SMTP), as demonstrated via the indexOfMail parameter to mwmail.asp.

    Source:Nine:Situations:Group
    Published:10 Aug 2009
    7.5
    High

    CVE-2008-6921

    Last Modified: 23 Jan 2017

    Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photoes/.

    Source:ahmadbady
    Published:10 Aug 2009
    7.5
    High

    CVE-2008-6920

    Last Modified: 23 Jan 2017

    Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension during a regnew action, then accessing it via a direct request to the file in photoes/.

    Source:ahmadbady
    Published:10 Aug 2009
    7.5
    High

    CVE-2008-6919

    Last Modified: 23 Apr 2026

    profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

    Source:cOndemned
    Published:10 Aug 2009
    6.8
    Medium

    CVE-2008-6918

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in galeria/.

    Source:siurek22
    Published:10 Aug 2009
    7.5
    High

    CVE-2008-6917

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQL commands via the username (user parameter).

    Source:Cyber-Zone
    Published:7 Aug 2009
    10
    Critical

    CVE-2008-6916

    Last Modified: 23 Apr 2026

    Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.

    Source:hkm
    Published:7 Aug 2009
    4.3
    Medium

    CVE-2008-6915

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or HTML via the propid parameter.

    Source:ZoRLu
    Published:7 Aug 2009
    6.5
    Medium

    CVE-2008-6914

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/.

    Source:ZoRLu
    Published:7 Aug 2009
    6.5
    Medium

    CVE-2008-6913

    Last Modified: 20 Dec 2016

    Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.

    Source:ZoRLu
    Published:7 Aug 2009
    7.5
    High

    CVE-2008-6912

    Last Modified: 23 Apr 2026

    Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.

    Source:G4N0K
    Published:7 Aug 2009
    6.8
    Medium

    CVE-2008-6911

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.

    Source:CWH Underground
    Published:6 Aug 2009
    6.8
    Medium

    CVE-2008-6907

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, as accessible from a form generated by index.php.

    Source:StAkeR
    Published:6 Aug 2009
    4.3
    Medium

    CVE-2008-6906

    Last Modified: 5 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in BabbleBoard 1.1.6 allows remote attackers to inject arbitrary web script or HTML via the username.

    Source:SirGod
    Published:6 Aug 2009
    6
    Medium

    CVE-2008-6905

    Last Modified: 5 Jan 2017

    Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to hijack the authentication of administrators for requests that delete (1) categories or (2) groups; (3) ban users; or (4) delete users via the admin page.

    Source:SirGod
    Published:6 Aug 2009
    6.8
    Medium

    CVE-2008-6902

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in flyers/.

    Source:Osirys
    Published:6 Aug 2009
    5.1
    Medium

    CVE-2008-6901

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in 2532designs 2532|Gigs 1.2.2 Stable, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) settings.php, (2) deleteuser.php, (3) mini_calendar.php, (4) manage_venues.php, and (5) manage_gigs.php, a different vector than CVE-2007-4585.

    Source:Osirys
    Published:6 Aug 2009
    6.5
    Medium

    CVE-2008-6900

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photos/.

    Source:S.W.A.T.
    Published:6 Aug 2009
    9
    Critical

    CVE-2008-6899

    Last Modified: 3 Dec 2016

    Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a long (1) open, (2) unlink, (3) mkdir, (4) rmdir, or (5) stat SFTP command.

    Source:r0ut3r
    Published:5 Aug 2009
    9.3
    Critical

    CVE-2008-6898

    Last Modified: 27 Apr 2011

    Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Get method and other unspecified methods.

    Source:Metasploit
    Published:5 Aug 2009
    9.3
    Critical

    CVE-2008-6897

    Last Modified: 23 Jan 2017

    Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) "a" HTML tag; a long src attribute in (2) embed, (3) img, or (4) script tags; (5) a long background attribute in a body tag; and other unspecified tags.

    Source:Koshi
    Published:5 Aug 2009
    7.5
    High

    CVE-2008-6892

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via the rubid parameter. NOTE: this might be the same issue as CVE-2005-3572.

    Source:SuB-ZeRo
    Published:3 Aug 2009
    4.3
    Medium

    CVE-2008-6891

    Last Modified: 1 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp.

    Source:Pouya_Server
    Published:3 Aug 2009
    7.5
    High

    CVE-2008-6890

    Last Modified: 1 Apr 2014

    SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter.

    Source:Pouya_Server
    Published:3 Aug 2009
    7.5
    High

    CVE-2008-6889

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.

    Source:R3d-D3V!L
    Published:3 Aug 2009
    4.3
    Medium

    CVE-2008-6888

    Last Modified: 31 Mar 2014

    Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter.

    Source:Pouya_Server
    Published:3 Aug 2009
    7.5
    High

    CVE-2008-6887

    Last Modified: 31 Mar 2014

    SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.

    Source:Pouya_Server
    Published:3 Aug 2009
    6.8
    Medium

    CVE-2008-6884

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter to (1) blocks.php and (2) main.php in xoops_lib/modules/protector/.

    Source:DSecRG
    Published:31 Jul 2009
    7.5
    High

    CVE-2008-6883

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:jdc
    Published:30 Jul 2009
    7.5
    High

    CVE-2008-6882

    Last Modified: 23 Apr 2026

    Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.

    Source:jdc
    Published:30 Jul 2009