7.5
    High

    CVE-2008-6881

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php.

    Source:jdc
    Published:30 Jul 2009
    7.5
    High

    CVE-2008-6880

    Last Modified: 3 Apr 2014

    SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Ehsan_Hp200
    Published:30 Jul 2009
    7.5
    High

    CVE-2008-6875

    Last Modified: 2 Jan 2014

    SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.

    Source:joseph.giron13
    Published:24 Jul 2009
    7.5
    High

    CVE-2008-6874

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQL commands via the iType parameter in (1) Auto1/type.asp or (2) auto2/type.asp.

    Source:AlpHaNiX
    Published:24 Jul 2009
    7.5
    High

    CVE-2008-6873

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.

    Source:R3d-D3V!L
    Published:23 Jul 2009
    5
    Medium

    CVE-2008-6872

    Last Modified: 23 Apr 2026

    ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb.

    Source:CWH Underground
    Published:23 Jul 2009
    5
    Medium

    CVE-2008-6871

    Last Modified: 23 Apr 2026

    Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.

    Source:ZoRLu
    Published:23 Jul 2009
    5
    Medium

    CVE-2008-6870

    Last Modified: 23 Apr 2026

    Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.

    Source:ZoRLu
    Published:23 Jul 2009
    5
    Medium

    CVE-2008-6869

    Last Modified: 23 Apr 2026

    Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini.

    Source:ahmadbady
    Published:23 Jul 2009
    7.5
    High

    CVE-2008-6867

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Source:Stack
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6864

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6863

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6862

    Last Modified: 23 Apr 2026

    Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6861

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:x0r
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6860

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6859

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6858

    Last Modified: 23 Apr 2026

    Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6857

    Last Modified: 23 Apr 2026

    Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6856

    Last Modified: 23 Apr 2026

    Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6855

    Last Modified: 23 Apr 2026

    Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6854

    Last Modified: 23 Apr 2026

    Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Source:Hakxer
    Published:14 Jul 2009
    7.5
    High

    CVE-2008-6853

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands via the PollID parameter.

    Source:s4avrd0w
    Published:7 Jul 2009
    7.5
    High

    CVE-2008-6852

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:boom3rang
    Published:7 Jul 2009
    5.1
    Medium

    CVE-2008-6851

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Source:fuzion
    Published:7 Jul 2009
    6.8
    Medium

    CVE-2008-6849

    Last Modified: 23 Jan 2017

    Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a via a link that is listed by userfiles/number_shell.php.

    Source:ahmadbady
    Published:7 Jul 2009
    4.3
    Medium

    CVE-2008-6848

    Last Modified: 23 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary web script or HTML via the category parameter in a select action.

    Source:ahmadbady
    Published:7 Jul 2009
    4.3
    Medium

    CVE-2008-6847

    Last Modified: 1 Apr 2014

    Cross-site scripting (XSS) vulnerability in Employee/emp_login.asp in Pre ASP Job Board allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:Pouya_Server
    Published:2 Jul 2009
    7.5
    High

    CVE-2008-6844

    Last Modified: 4 Jan 2017

    The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote attackers to gain privileges as other users via modified ContentObjectAttribute_data_user_login_30, ContentObjectAttribute_data_user_password_30, and other parameters.

    Source:s4avrd0w
    Published:2 Jul 2009
    5
    Medium

    CVE-2008-6843

    Last Modified: 1 Apr 2014

    Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter.

    Source:Super-Crystal
    Published:2 Jul 2009
    6.8
    Medium

    CVE-2008-6842

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the post parameter.

    Source:Alfons Luja
    Published:2 Jul 2009
    7.5
    High

    CVE-2008-6841

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to classes/DBQ/admin/common.class.php.

    Source:SsEs
    Published:1 Jul 2009
    6.8
    Medium

    CVE-2008-6840

    Last Modified: 3 Mar 2014

    Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[pear_dir] parameter to (a) Mail/RFC822.php, (b) Net/Socket.php, (c) XML/Parser.php, (d) XML/Tree.php, (e) Mail/mimeDecode.php, (f) Console/Getopt.php, (g) System.php, (h) Log.php, and (i) File.php in includes/pear/; the CONFIG[pear_dir] parameter to (j) includes/prepend.php, and (k) includes/cachedConfig.php; and the (2) CONFIG[includes] parameter to (l) prepend.php and (m) email.list.search.php in includes/. NOTE: the CONFIG[pear_dir] parameter to includes/mailaccess/pop3.php is already covered by CVE-2006-2666.

    Source:CraCkEr
    Published:1 Jul 2009
    4.3
    Medium

    CVE-2008-6839

    Last Modified: 3 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) login.php and (b) index.php, and the (3) dir and (4) id parameters to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Julian Rodriguez
    Published:27 Jun 2009
    4.3
    Medium

    CVE-2008-6838

    Last Modified: 3 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to inject arbitrary web script or HTML via the _off parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Julian Rodriguez
    Published:27 Jun 2009
    7.5
    High

    CVE-2008-6837

    Last Modified: 3 Mar 2014

    SQL injection vulnerability in Zoph 0.7.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different issue than CVE-2008-3258. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Julian Rodriguez
    Published:27 Jun 2009
    10
    Critical

    CVE-2008-6834

    Last Modified: 13 Dec 2016

    Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s parameter to code/commupdate.php in a count action or (2) the heads parameter to code/newsheads.php. NOTE: the blog.php vector is already covered by CVE-2008-3164.

    Source:Cod3rZ
    Published:22 Jun 2009
    10
    Critical

    CVE-2008-6833

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.

    Source:Charles Fol
    Published:22 Jun 2009
    5
    Medium

    CVE-2008-6829

    Last Modified: 23 Apr 2026

    VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.

    Source:Alfons Luja
    Published:8 Jun 2009
    7.8
    High

    CVE-2008-6827

    Last Modified: 23 Apr 2026

    The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.

    Published:8 Jun 2009
    10
    Critical

    CVE-2008-6826

    Last Modified: 23 Apr 2026

    dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter, as demonstrated using the (1) advert_top.htm or (2) advert_login.htm pages.

    Source:S0l1D
    Published:8 Jun 2009
    6.8
    Medium

    CVE-2008-6825

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.

    Source:muts
    Published:5 Jun 2009
    10
    Critical

    CVE-2008-6824

    Last Modified: 23 Apr 2026

    The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier for remote attackers to obtain access.

    Source:Henri Lindberg
    Published:4 Jun 2009
    6.8
    Medium

    CVE-2008-6823

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.

    Source:Henri Lindberg
    Published:4 Jun 2009
    7.5
    High

    CVE-2008-6822

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by an upload with an image/jpeg content type. NOTE: some of these details are obtained from third party information.

    Source:Dentrasi
    Published:4 Jun 2009
    5
    Medium

    CVE-2008-6815

    Last Modified: 23 Apr 2026

    mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.

    Source:Stack
    Published:28 May 2009
    6.8
    Medium

    CVE-2008-6814

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg content type, then accessing this file via a direct request to the file in components/com_simpleboard/, a different vulnerability than CVE-2006-3528.

    Source:t0pP8uZz
    Published:28 May 2009
    7.5
    High

    CVE-2008-6813

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the id_kat parameter.

    Source:storm
    Published:21 May 2009
    7.5
    High

    CVE-2008-6812

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.

    Source:Virangar Security
    Published:21 May 2009
    6.8
    Medium

    CVE-2008-6811

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/plugins/wp-shopping-cart/.

    Source:t0pP8uZz
    Published:17 May 2009
    7.5
    High

    CVE-2008-6810

    Last Modified: 3 Jan 2017

    Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Source:MrDoug
    Published:17 May 2009