5
    Medium

    CVE-2008-6580

    Last Modified: 23 Apr 2026

    The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.

    Source:Cyber-Zone
    Published:2 Apr 2009
    6.8
    Medium

    CVE-2008-6572

    Last Modified: 22 Feb 2014

    SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Source:Ali Jasbi
    Published:31 Mar 2009
    4.3
    Medium

    CVE-2008-6565

    Last Modified: 10 Feb 2014

    Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.

    Source:SHAHEE_MIRZA
    Published:31 Mar 2009
    9.3
    Critical

    CVE-2008-6563

    Last Modified: 13 Feb 2014

    Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DTD file.

    Source:david130490
    Published:31 Mar 2009
    4.3
    Medium

    CVE-2008-6562

    Last Modified: 11 Feb 2014

    Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:31 Mar 2009
    7.2
    High

    CVE-2008-6559

    Last Modified: 17 Nov 2016

    Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. (dot dot) sequences that point to a directory containing a file whose name includes shell metacharacters.

    Source:qaaz
    Published:30 Mar 2009
    7.2
    High

    CVE-2008-6558

    Last Modified: 17 Nov 2016

    Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program.

    Source:qaaz
    Published:30 Mar 2009
    10
    Critical

    CVE-2008-6555

    Last Modified: 7 Feb 2014

    cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command.

    Source:Zero X
    Published:30 Mar 2009
    7.5
    High

    CVE-2008-6553

    Last Modified: 23 Apr 2026

    microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify administrative passwords via a change_password action.

    Source:StAkeR
    Published:30 Mar 2009
    5.1
    Medium

    CVE-2008-6551

    Last Modified: 6 Jan 2017

    Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.

    Source:StAkeR
    Published:30 Mar 2009
    4.3
    Medium

    CVE-2008-6550

    Last Modified: 12 Feb 2014

    Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:30 Mar 2009
    7.5
    High

    CVE-2008-6545

    Last Modified: 12 Feb 2014

    PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:30 Mar 2009
    7.5
    High

    CVE-2008-6544

    Last Modified: 9 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter to Sources/Themes.php. NOTE: CVE and multiple third parties dispute this issue because the files contain a protection mechanism against direct request

    Source:Sibertrwolf
    Published:30 Mar 2009
    7.5
    High

    CVE-2008-6543

    Last Modified: 7 Feb 2014

    Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classifieds/index.php3, and (5) classifieds/view.php3; (6) index.php3, (7) manager.php3, (8) pass.php3, (9) remember.php3 (10) sign-up.php3, (11) update.php3, (12) userSet.php3, and (13) verify.php3 in controlcenter/; (14) alterCats.php3, (15) alterFeatured.php3, (16) alterHomepage.php3, (17) alterNews.php3, (18) alterTheme.php3, (19) color_help.php3, (20) createdb.php3, (21) createFeatured.php3, (22) createHomepage.php3, (23) createL.php3, (24) createM.php3, (25) createNews.php3, (26) createP.php3, (27) createS.php3, (28) createT.php3, (29) index.php3, (30) mailadmin.php3, and (31) setUp.php3 in controlpannel/; (32) include/sendit.php3 and (33) include/sendit2.php3; and possibly (34) include/adminHead.inc, (35) include/usersHead.inc, and (36) style/default.scheme.inc.

    Source:ZoRLu
    Published:30 Mar 2009
    5.1
    Medium

    CVE-2008-6540

    Last Modified: 6 Feb 2014

    DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.

    Source:Brian Holyfield
    Published:30 Mar 2009
    6.5
    Medium

    CVE-2008-6539

    Last Modified: 16 Nov 2016

    Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

    Source:nonroot
    Published:30 Mar 2009
    5
    Medium

    CVE-2008-6538

    Last Modified: 16 Nov 2016

    DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

    Source:nonroot
    Published:30 Mar 2009
    5
    Medium

    CVE-2008-6537

    Last Modified: 23 Apr 2026

    LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later accessed using $_REQUEST.

    Source:girex
    Published:30 Mar 2009
    7.5
    High

    CVE-2008-6535

    Last Modified: 4 Jan 2017

    admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the administrative password via a direct request with a modified NewAdmin parameter.

    Source:G4N0K
    Published:26 Mar 2009
    7.1
    High

    CVE-2008-6534

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute arbitrary commands via a custom SITE command containing shell metacharacters such as "&" (ampersand) in the middle of an argument.

    Source:Tan Chew Keong
    Published:26 Mar 2009
    6.5
    Medium

    CVE-2008-6530

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file.

    Source:Bgh7
    Published:26 Mar 2009
    4.3
    Medium

    CVE-2008-6529

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inject arbitrary web script or HTML via the r parameter.

    Source:Bgh7
    Published:26 Mar 2009
    5
    Medium

    CVE-2008-6528

    Last Modified: 23 Apr 2026

    NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.

    Source:Simon Ryeo
    Published:26 Mar 2009
    7.5
    High

    CVE-2008-6527

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.

    Source:Bl@ckbe@rD
    Published:25 Mar 2009
    7.5
    High

    CVE-2008-6526

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.

    Source:ZoRLu
    Published:25 Mar 2009
    7.5
    High

    CVE-2008-6525

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to execute arbitrary SQL commands via the Password parameter (aka the pass field).

    Source:r45c4l
    Published:25 Mar 2009
    6.5
    Medium

    CVE-2008-6524

    Last Modified: 23 Apr 2026

    resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

    Source:t0pP8uZz
    Published:25 Mar 2009
    7.5
    High

    CVE-2008-6523

    Last Modified: 23 Apr 2026

    auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.

    Source:t0pP8uZz
    Published:25 Mar 2009
    6.8
    Medium

    CVE-2008-6522

    Last Modified: 12 Feb 2014

    Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the (1) CurrentDirectory and (2) File parameters to index.php.

    Source:Joseph Giron
    Published:25 Mar 2009
    10
    Critical

    CVE-2008-6519

    Last Modified: 23 Apr 2026

    Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a Long Running Web Process (LRWP) request, which triggers incorrect logging code involving the sendfmt function in the SMT kernel.

    Source:bratax
    Published:25 Mar 2009
    6.5
    Medium

    CVE-2008-6518

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request.

    Source:InjEctOr5
    Published:25 Mar 2009
    7.5
    High

    CVE-2008-6517

    Last Modified: 14 Mar 2014

    SQL injection vulnerability in NewsHOWLER 1.03 Beta allows remote attackers to execute arbitrary SQL commands via the news_user cookie parameter.

    Source:Khashayar Fereidani
    Published:25 Mar 2009
    7.5
    High

    CVE-2008-6516

    Last Modified: 11 Mar 2014

    Multiple directory traversal vulnerabilities in phpKF-Portal 1.10 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) tema_dizin parameter to baslik.php and (2) portal_ayarlarportal_dili parameter to anket_yonetim.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:KnocKout
    Published:25 Mar 2009
    4.3
    Medium

    CVE-2008-6515

    Last Modified: 29 Dec 2016

    Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

    Source:Pouya_Server
    Published:24 Mar 2009
    6.8
    Medium

    CVE-2008-6513

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php.

    Source:CWH Underground
    Published:24 Mar 2009
    5.8
    Medium

    CVE-2008-6511

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.

    Source:Andreas Kurtz
    Published:23 Mar 2009
    4.3
    Medium

    CVE-2008-6510

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Source:Andreas Kurtz
    Published:23 Mar 2009
    7.5
    High

    CVE-2008-6509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.

    Source:Andreas Kurtz
    Published:23 Mar 2009
    7.5
    High

    CVE-2008-6508

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.

    Source:Metasploit
    Published:23 Mar 2009
    5
    Medium

    CVE-2008-6505

    Last Modified: 28 Mar 2014

    Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.

    Source:Csaba Barta
    Published:23 Mar 2009
    5
    Medium

    CVE-2008-6504

    Last Modified: 28 Mar 2014

    ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.

    Source:Meder Kydyraliev
    Published:12 Jun 2008
    4.3
    Medium

    CVE-2008-6503

    Last Modified: 2 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php.

    Source:th3.r00k.ieatpork
    Published:20 Mar 2009
    4.6
    Medium

    CVE-2008-6502

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts.

    Source:ZynbER
    Published:20 Mar 2009
    4.3
    Medium

    CVE-2008-6501

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter.

    Source:ZynbER
    Published:20 Mar 2009
    4.3
    Medium

    CVE-2008-6500

    Last Modified: 31 Mar 2014

    Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

    Source:Pouya_Server
    Published:20 Mar 2009
    5.5
    Medium

    CVE-2008-6499

    Last Modified: 6 Jan 2017

    security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.

    Source:Michael Brooks
    Published:20 Mar 2009
    6.8
    Medium

    CVE-2008-6498

    Last Modified: 6 Jan 2017

    Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.

    Source:bi0
    Published:20 Mar 2009
    7.8
    High

    CVE-2008-6497

    Last Modified: 23 Apr 2026

    The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI.

    Source:0in
    Published:20 Mar 2009
    8.8
    High

    CVE-2008-6496

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.

    Source:Marco Torti
    Published:20 Mar 2009
    4.3
    Medium

    CVE-2008-6495

    Last Modified: 29 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Source:Pouya_Server
    Published:20 Mar 2009