7.5
    High

    CVE-2008-6741

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "\" (backslash) sequence that does not quote the "'" (single quote) character, as demonstrated via a manlabels action to index.php.

    Source:The:Paradox
    Published:21 Apr 2009
    6.8
    Medium

    CVE-2008-6740

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the _settings[pluginpath] parameter.

    Source:CraCkEr
    Published:21 Apr 2009
    7.5
    High

    CVE-2008-6739

    Last Modified: 23 Apr 2026

    Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows remote attackers to gain administrator privileges via a direct request.

    Source:Zigma
    Published:21 Apr 2009
    7.5
    High

    CVE-2008-6738

    Last Modified: 23 Apr 2026

    MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.

    Source:Stack
    Published:21 Apr 2009
    7.8
    High

    CVE-2008-6737

    Last Modified: 27 Feb 2014

    Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.

    Source:Luigi Auriemma
    Published:21 Apr 2009
    6.4
    Medium

    CVE-2008-6736

    Last Modified: 26 Feb 2014

    Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

    Source:Crackers_Child
    Published:21 Apr 2009
    5.8
    Medium

    CVE-2008-6735

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the sLanguage cookie.

    Source:CWH Underground
    Published:21 Apr 2009
    9.3
    Critical

    CVE-2008-6734

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.

    Source:CWH Underground
    Published:21 Apr 2009
    9.3
    Critical

    CVE-2008-6731

    Last Modified: 23 Jan 2017

    Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the renamed file in linkphoto/.

    Source:Osirys
    Published:20 Apr 2009
    6.8
    Medium

    CVE-2008-6730

    Last Modified: 10 Jan 2017

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php.

    Source:x0r
    Published:20 Apr 2009
    6.8
    Medium

    CVE-2008-6729

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that modify an account via the (1) password or (2) email_address parameter.

    Source:Ausome1
    Published:20 Apr 2009
    4.3
    Medium

    CVE-2008-6727

    Last Modified: 10 Jan 2017

    Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Source:StAkeR
    Published:20 Apr 2009
    6
    Medium

    CVE-2008-6726

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415.

    Source:SirGod
    Published:17 Apr 2009
    6
    Medium

    CVE-2008-6725

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.

    Source:SirGod
    Published:17 Apr 2009
    7.5
    High

    CVE-2008-6723

    Last Modified: 23 Apr 2026

    TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLogged cookie to Administrator.

    Source:G4N0K
    Published:14 Apr 2009
    7.5
    High

    CVE-2008-6721

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).

    Source:Hakxer
    Published:14 Apr 2009
    7.5
    High

    CVE-2008-6720

    Last Modified: 16 Aug 2015

    SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).

    Source:L0n3ly-H34rT
    Published:13 Apr 2009
    7.5
    High

    CVE-2008-6719

    Last Modified: 23 Apr 2026

    U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) start.php, (2) aktivitet.php, (3) prop_aktivitet.php, (4) kategorier.php, (5) konfig.php, (6) security.php, (7) manual.php, and possibly (8) index.php.

    Source:G4N0K
    Published:13 Apr 2009
    7.5
    High

    CVE-2008-6718

    Last Modified: 23 Apr 2026

    U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) user_manual.php, (2) user_config.php, (3) user_kundnamn.php, (4) user_kundlista.php, (5) user_aktiva_kunder.php, (6) database.php, and possibly (7) index.php.

    Source:G4N0K
    Published:13 Apr 2009
    7.5
    High

    CVE-2008-6717

    Last Modified: 23 Apr 2026

    U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php.

    Source:G4N0K
    Published:13 Apr 2009
    7.5
    High

    CVE-2008-6716

    Last Modified: 6 Dec 2016

    homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to have an unspecified impact via a direct request.

    Source:G4N0K
    Published:13 Apr 2009
    4.3
    Medium

    CVE-2008-6715

    Last Modified: 6 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) homeadmin/adminhome.php and (2) homeadmin/signinform.php.

    Source:G4N0K
    Published:13 Apr 2009
    7.5
    High

    CVE-2008-6714

    Last Modified: 7 Dec 2016

    admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.

    Source:t0pP8uZz
    Published:10 Apr 2009
    5
    Medium

    CVE-2008-6713

    Last Modified: 3 Mar 2014

    World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:10 Apr 2009
    5
    Medium

    CVE-2008-6712

    Last Modified: 27 Feb 2014

    The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:10 Apr 2009
    10
    Critical

    CVE-2008-6703

    Last Modified: 3 Mar 2014

    Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.

    Source:Luigi Auriemma
    Published:10 Apr 2009
    5
    Medium

    CVE-2008-6702

    Last Modified: 26 Feb 2014

    S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.

    Source:Luigi Auriemma
    Published:10 Apr 2009
    4.3
    Medium

    CVE-2008-6700

    Last Modified: 6 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php.

    Source:CWH Underground
    Published:10 Apr 2009
    4.3
    Medium

    CVE-2008-6683

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter.

    Source:ZoRLu
    Published:10 Apr 2009
    7.5
    High

    CVE-2008-6678

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile action to default.asp.

    Source:BugReport.IR
    Published:8 Apr 2009
    7.5
    High

    CVE-2008-6677

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.

    Source:BugReport.IR
    Published:8 Apr 2009
    5
    Medium

    CVE-2008-6676

    Last Modified: 23 Apr 2026

    QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message.

    Source:BugReport.IR
    Published:8 Apr 2009
    4.3
    Medium

    CVE-2008-6675

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3) SB_feedback parameters in process_send.asp, as reachable through default.asp; (4) paramCode and (5) cColor parameters to picker.asp; and the (6) query string, (7) Referer header, and (8) X-FORWARDED-FOR header to rss.asp.

    Source:BugReport.IR
    Published:8 Apr 2009
    5
    Medium

    CVE-2008-6674

    Last Modified: 23 Apr 2026

    mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail parameter.

    Source:BugReport.IR
    Published:8 Apr 2009
    7.5
    High

    CVE-2008-6673

    Last Modified: 23 Apr 2026

    asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact address, via the saveAdmin; and (3) modify the site design via the saveDesign action.

    Source:BugReport.IR
    Published:8 Apr 2009
    5
    Medium

    CVE-2008-6670

    Last Modified: 3 Mar 2014

    Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960.

    Source:Luigi Auriemma
    Published:8 Apr 2009
    7.5
    High

    CVE-2008-6669

    Last Modified: 9 Dec 2016

    viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.

    Source:dun
    Published:8 Apr 2009
    5
    Medium

    CVE-2008-6668

    Last Modified: 9 Dec 2016

    Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.

    Source:dun
    Published:8 Apr 2009
    7.5
    High

    CVE-2008-6667

    Last Modified: 23 Apr 2026

    A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.

    Source:Virangar Security
    Published:8 Apr 2009
    6.8
    Medium

    CVE-2008-6665

    Last Modified: 9 Dec 2016

    change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.

    Source:CWH Underground
    Published:8 Apr 2009
    7.5
    High

    CVE-2008-6664

    Last Modified: 23 Apr 2026

    action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

    Source:Virangar Security
    Published:8 Apr 2009
    7.5
    High

    CVE-2008-6663

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106.

    Source:Mr.SQL
    Published:8 Apr 2009
    6.8
    Medium

    CVE-2008-6660

    Last Modified: 24 Mar 2014

    Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct request. NOTE: some of these details are obtained from third party information.

    Source:felipe andrian
    Published:7 Apr 2009
    5.5
    Medium

    CVE-2008-6659

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to Sources/QueryString.php and Sources/Themes.php, as demonstrated by a local .gif file in attachments/ with PHP code that was uploaded through a profile2 action to index.php.

    Source:~elmysterio
    Published:7 Apr 2009
    4
    Medium

    CVE-2008-6658

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.

    Source:Charles Fol
    Published:7 Apr 2009
    6.8
    Medium

    CVE-2008-6657

    Last Modified: 9 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

    Source:Charles Fol
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6656

    Last Modified: 2 Dec 2016

    Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php.

    Source:InjEctOr5
    Published:7 Apr 2009
    4.3
    Medium

    CVE-2008-6655

    Last Modified: 18 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche and (2) nom parameters to php/prenom.php; the (3) nom_branche parameter to php/index.php; and the (4) nom_branche, (5) nom, and (6) prenom parameters to php/info.php.

    Source:ZoRLu
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6653

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:cO2
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6652

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter.

    Source:Cod3rZ
    Published:7 Apr 2009