10
    Critical

    CVE-2008-6651

    Last Modified: 25 Nov 2016

    Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter.

    Source:GoLd_M
    Published:7 Apr 2009
    5
    Medium

    CVE-2008-6650

    Last Modified: 28 Nov 2016

    del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_id parameter, a different vulnerability than CVE-2008-4628.

    Source:Cod3rZ
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6649

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versions through 3.5.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mr.SQL
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6648

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter to about_us.php. NOTE: this might be the same issue as CVE-2008-6647.

    Source:Mr.SQL
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6647

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL commands via the gid parameter.

    Source:Mr.SQL
    Published:7 Apr 2009
    4.3
    Medium

    CVE-2008-6644

    Last Modified: 24 Feb 2014

    Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:AmnPardaz Security Research Team
    Published:7 Apr 2009
    5
    Medium

    CVE-2008-6643

    Last Modified: 21 Nov 2016

    LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php.

    Source:girex
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6642

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL commands via the sid parameter. NOTE: some of these details are obtained from third party information.

    Source:cO2
    Published:7 Apr 2009
    6.5
    Medium

    CVE-2008-6641

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp.

    Source:U238
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6640

    Last Modified: 19 Feb 2014

    Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) uyeadmin.asp and (2) profil.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:U238
    Published:7 Apr 2009
    4.3
    Medium

    CVE-2008-6637

    Last Modified: 23 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in forgotPW.php in Library Video Company SAFARI Montage 3.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) school and (2) email parameters.

    Source:Omer Singer
    Published:7 Apr 2009
    6.8
    Medium

    CVE-2008-6636

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_edge_skins parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CraCkEr
    Published:7 Apr 2009
    6.8
    Medium

    CVE-2008-6635

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_inc parameter.

    Source:CraCkEr
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6634

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php.

    Source:Virangar Security
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6633

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php.

    Source:His0k4
    Published:7 Apr 2009
    7.5
    High

    CVE-2008-6632

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).

    Source:EgiX
    Published:7 Apr 2009
    4.3
    Medium

    CVE-2008-6631

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendmessage action and the (2) username parameter when registering a new user, different vectors than CVE-2008-0679.

    Source:David Sopas Ferreira
    Published:7 Apr 2009
    4.3
    Medium

    CVE-2008-6629

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Source:G4N0K
    Published:6 Apr 2009
    Low

    CVE-2008-6628

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-6268. Reason: This candidate is a duplicate of CVE-2008-6268. Notes: All CVE users should reference CVE-2008-6268 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:G4N0K
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6627

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Hakxer
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6626

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Hakxer
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6625

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Hakxer
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6624

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Hakxer
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6623

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in getin.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:x0r
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6622

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Hussin X
    Published:6 Apr 2009
    4.3
    Medium

    CVE-2008-6620

    Last Modified: 23 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in javascript/editor/editor/filemanager/browser/mcpuk/connectors/php/connector.php in GraFX miniCWB 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errcontext, (2) _GET, (3) _POST, (4) _SESSION, (5) _SERVER, and (6) fckphp_config[Debug_SERVER] parameters.

    Source:CWH Underground
    Published:6 Apr 2009
    6.8
    Medium

    CVE-2008-6619

    Last Modified: 23 Feb 2014

    Unrestricted file upload vulnerability in class/ApplyDB.php in ClassSystem 2.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in class/UploadHomepage/.

    Source:Unohope
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6618

    Last Modified: 23 Feb 2014

    Multiple SQL injection vulnerabilities in ClassSystem 2.3 allow remote attackers to execute arbitrary SQL commands via the teacher_id parameter in (1) class/HomepageMain.php and (2) class/HomepageTop.php, and (3) the message_id parameter in class/MessageReply.php.

    Source:Unohope
    Published:6 Apr 2009
    6.8
    Medium

    CVE-2008-6617

    Last Modified: 9 Dec 2016

    Unrestricted file upload vulnerability in adm/visual/upload.php in SiteXS CMS 0.1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

    Source:Hadi Kiamarsi
    Published:6 Apr 2009
    4.3
    Medium

    CVE-2008-6616

    Last Modified: 18 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ivan Sanchez
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6615

    Last Modified: 18 Feb 2014

    SQL injection vulnerability in index.php in Zen Software Zen Cart 2008 allows remote attackers to execute arbitrary SQL commands via the keyword parameter in the advanced_search_result page. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ivan Sanchez
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6613

    Last Modified: 6 Jan 2017

    uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request.

    Source:NoGe
    Published:6 Apr 2009
    6.8
    Medium

    CVE-2008-6612

    Last Modified: 6 Jan 2017

    Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.

    Source:NoGe
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6611

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:NoGe
    Published:6 Apr 2009
    4.3
    Medium

    CVE-2008-6609

    Last Modified: 3 Apr 2014

    Cross-site scripting (XSS) vulnerability in phpcksec.php in Stefan Ott phpcksec 0.2 allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Source:ahmadbady
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6608

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.php, (2) the user_pass parameter (aka pass field) to admin/index.php, or (3) the id parameter to calendar_details.php. NOTE: some of these details are obtained from third party information.

    Source:InjEctOr5
    Published:6 Apr 2009
    4.3
    Medium

    CVE-2008-6607

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to inject arbitrary web script or HTML via the thema parameter.

    Source:Hakxer
    Published:6 Apr 2009
    7.5
    High

    CVE-2008-6606

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hakxer
    Published:6 Apr 2009
    6.8
    Medium

    CVE-2008-6605

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.51 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that cause a denial of service (network outage) via a page parameter with a % (percent) character followed by a non-alphanumeric character.

    Source:hkm
    Published:6 Apr 2009
    10
    Critical

    CVE-2008-6604

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulnerability than CVE-2007-5390.

    Source:gmda
    Published:4 Apr 2009
    4.3
    Medium

    CVE-2008-6597

    Last Modified: 17 Feb 2014

    Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:3 Apr 2009
    7.5
    High

    CVE-2008-6596

    Last Modified: 17 Feb 2014

    SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL commands via the hash parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:3 Apr 2009
    7.5
    High

    CVE-2008-6593

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.

    Source:girex
    Published:3 Apr 2009
    7.5
    High

    CVE-2008-6592

    Last Modified: 21 Nov 2016

    thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).

    Source:girex
    Published:3 Apr 2009
    5
    Medium

    CVE-2008-6590

    Last Modified: 21 Nov 2016

    Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to (1) index.php and (2) LightNEasy.php.

    Source:girex
    Published:3 Apr 2009
    6.8
    Medium

    CVE-2008-6586

    Last Modified: 9 Mar 2018

    Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests that modify the administrator account via the setsetting action.

    Source:th3.r00k
    Published:3 Apr 2009
    6.8
    Medium

    CVE-2008-6585

    Last Modified: 14 Feb 2014

    Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via the addUser action.

    Source:Michael Brooks
    Published:3 Apr 2009
    9.3
    Critical

    CVE-2008-6583

    Last Modified: 23 Apr 2026

    Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file.

    Source:j0rgan
    Published:3 Apr 2009
    7.5
    High

    CVE-2008-6582

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Source:HaCkeR_EgY
    Published:2 Apr 2009
    7.5
    High

    CVE-2008-6581

    Last Modified: 6 Jan 2017

    login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

    Source:x0r
    Published:2 Apr 2009