7.5
    High

    CVE-2008-6809

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter.

    Source:R3d-D3V!L
    Published:17 May 2009
    7.5
    High

    CVE-2008-6808

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:BeyazKurt
    Published:12 May 2009
    7.5
    High

    CVE-2008-6807

    Last Modified: 26 Mar 2014

    PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xml_dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the lib_dir vector is already covered by CVE-2006-6630.

    Source:BoZKuRTSeRDaR
    Published:12 May 2009
    6.8
    Medium

    CVE-2008-6806

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/artikel/.

    Source:t0pP8uZz
    Published:12 May 2009
    6.8
    Medium

    CVE-2008-6805

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mic_Blog 0.0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to category.php, the (2) user parameter to login.php, and the (3) site parameter to register.php.

    Source:StAkeR
    Published:11 May 2009
    7.5
    High

    CVE-2008-6804

    Last Modified: 23 Apr 2026

    Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue

    Source:ZoRLu
    Published:11 May 2009
    7.5
    High

    CVE-2008-6803

    Last Modified: 25 Mar 2014

    SQL injection vulnerability in diziler.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CyberGrup Lojistik
    Published:11 May 2009
    7.5
    High

    CVE-2008-6802

    Last Modified: 25 Mar 2014

    Multiple SQL injection vulnerabilities in index.php in phPhotoGallery 0.92 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:KnocKout
    Published:7 May 2009
    7.5
    High

    CVE-2008-6799

    Last Modified: 25 Mar 2014

    connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative privileges by setting the s parameter to "7."

    Source:eLiSiA
    Published:7 May 2009
    7.5
    High

    CVE-2008-6798

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).

    Source:BackDoor
    Published:7 May 2009
    7.5
    High

    CVE-2008-6796

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).

    Source:Cyber-Zone
    Published:7 May 2009
    7.5
    High

    CVE-2008-6795

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL commands via the nID parameter.

    Source:StAkeR
    Published:7 May 2009
    7.5
    High

    CVE-2008-6794

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Hakxer
    Published:7 May 2009
    6.8
    Medium

    CVE-2008-6793

    Last Modified: 23 Apr 2026

    The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters after an arg1= sequence in a filename within a forensic image.

    Source:ikki
    Published:7 May 2009
    5
    Medium

    CVE-2008-6791

    Last Modified: 23 Apr 2026

    PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field.

    Source:Saint Patrick
    Published:4 May 2009
    5.1
    Medium

    CVE-2008-6790

    Last Modified: 23 Apr 2026

    The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.

    Source:CWH Underground
    Published:4 May 2009
    5.1
    Medium

    CVE-2008-6789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.

    Source:CWH Underground
    Published:4 May 2009
    5.1
    Medium

    CVE-2008-6788

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.

    Source:CWH Underground
    Published:4 May 2009
    7.5
    High

    CVE-2008-6787

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user.

    Source:StAkeR
    Published:1 May 2009
    6.8
    Medium

    CVE-2008-6785

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file.

    Source:MR.Z
    Published:1 May 2009
    7.5
    High

    CVE-2008-6784

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:Hurley
    Published:1 May 2009
    7.5
    High

    CVE-2008-6783

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:BeyazKurt
    Published:1 May 2009
    7.5
    High

    CVE-2008-6782

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:BeyazKurt
    Published:1 May 2009
    7.5
    High

    CVE-2008-6781

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:BeyazKurt
    Published:1 May 2009
    7.5
    High

    CVE-2008-6780

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:d3b4g
    Published:1 May 2009
    7.5
    High

    CVE-2008-6779

    Last Modified: 25 Mar 2014

    SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.php.

    Source:r45c4l
    Published:1 May 2009
    7.5
    High

    CVE-2008-6778

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Stack
    Published:1 May 2009
    5.1
    Medium

    CVE-2008-6777

    Last Modified: 30 Oct 2017

    Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.

    Source:StAkeR
    Published:1 May 2009
    7.5
    High

    CVE-2008-6776

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to execute arbitrary SQL commands via the phid parameter.

    Source:d3b4g
    Published:1 May 2009
    7.1
    High

    CVE-2008-6775

    Last Modified: 23 Apr 2026

    HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectivity loss) via a flood of vCards to UDP port 9204.

    Source:Mobile Security Lab
    Published:1 May 2009
    6.5
    Medium

    CVE-2008-6773

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary PHP code into user/internettoolbar/index.php via the (1) fav1_url, (2) fav1_name, (3) fav2_url, (4) fav2_name, (5) fav3_url, (6) fav3_name, (7) fav4_url, (8) fav4_name, (9) fav5_url, or (10) fav5_name parameters.

    Source:Osirys
    Published:29 Apr 2009
    7.5
    High

    CVE-2008-6772

    Last Modified: 23 Apr 2026

    login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account is created, which allows remote attackers to bypass intended access restrictions by registering a new account with the username of a target user.

    Source:Osirys
    Published:29 Apr 2009
    5
    Medium

    CVE-2008-6771

    Last Modified: 23 Apr 2026

    YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function.

    Source:Osirys
    Published:29 Apr 2009
    5
    Medium

    CVE-2008-6770

    Last Modified: 23 Apr 2026

    YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.

    Source:Osirys
    Published:29 Apr 2009
    6
    Medium

    CVE-2008-6769

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.

    Source:Osirys
    Published:29 Apr 2009
    6.8
    Medium

    CVE-2008-6768

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/.

    Source:mNt
    Published:29 Apr 2009
    5
    Medium

    CVE-2008-6765

    Last Modified: 14 Dec 2016

    ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.

    Source:Xia Shing Zee
    Published:28 Apr 2009
    4.3
    Medium

    CVE-2008-6764

    Last Modified: 18 Mar 2014

    Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:Maximiliano Soler
    Published:28 Apr 2009
    7.5
    High

    CVE-2008-6763

    Last Modified: 23 Apr 2026

    login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.

    Source:Osirys
    Published:28 Apr 2009
    10
    Critical

    CVE-2008-6761

    Last Modified: 23 Jan 2017

    Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the Database Name field). NOTE: the installation instructions specify deleting admin/install.php.

    Source:Osirys
    Published:28 Apr 2009
    6.8
    Medium

    CVE-2008-6758

    Last Modified: 14 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.

    Source:Xia Shing Zee
    Published:28 Apr 2009
    4.3
    Medium

    CVE-2008-6757

    Last Modified: 4 Apr 2014

    Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.

    Source:Xia Shing Zee
    Published:28 Apr 2009
    7.5
    High

    CVE-2008-6752

    Last Modified: 4 Jan 2017

    adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password and gain privileges via a direct request with modified newpass1 and newpass2 parameters in a Change operation.

    Source:G4N0K
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2008-6751

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo.

    Source:S.W.A.T.
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2008-6750

    Last Modified: 23 Jan 2017

    Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.

    Source:x0r
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2008-6749

    Last Modified: 23 Jan 2017

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters.

    Source:x0r
    Published:24 Apr 2009
    9.3
    Critical

    CVE-2008-6748

    Last Modified: 3 Nov 2016

    Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.

    Source:JJunior
    Published:24 Apr 2009
    7.5
    High

    CVE-2008-6745

    Last Modified: 9 Dec 2016

    index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action.

    Source:Cod3rZ
    Published:23 Apr 2009
    7.5
    High

    CVE-2008-6743

    Last Modified: 23 Apr 2026

    RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

    Source:Osirys
    Published:22 Apr 2009
    4.3
    Medium

    CVE-2008-6742

    Last Modified: 23 Apr 2026

    Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value.

    Source:Styxosaurus
    Published:21 Apr 2009