5
    Medium

    CVE-2008-6494

    Last Modified: 23 Apr 2026

    ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb.

    Source:AlpHaNiX
    Published:20 Mar 2009
    5
    Medium

    CVE-2008-6493

    Last Modified: 4 Jan 2017

    Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb.

    Source:BeyazKurt
    Published:20 Mar 2009
    6.8
    Medium

    CVE-2008-6492

    Last Modified: 6 Jan 2017

    Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information.

    Source:ahmadbady
    Published:20 Mar 2009
    7.5
    High

    CVE-2008-6491

    Last Modified: 12 Feb 2014

    PHP remote file inclusion vulnerability in connexion.php in PHPGKit 0.9 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:19 Mar 2009
    7.5
    High

    CVE-2008-6490

    Last Modified: 24 Nov 2016

    function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.

    Source:EgiX
    Published:19 Mar 2009
    7.5
    High

    CVE-2008-6489

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.

    Source:parad0x
    Published:19 Mar 2009
    7.5
    High

    CVE-2008-6488

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.

    Source:Hussin X
    Published:18 Mar 2009
    7.5
    High

    CVE-2008-6487

    Last Modified: 2 Jan 2017

    Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.

    Source:d3b4g
    Published:18 Mar 2009
    7.5
    High

    CVE-2008-6485

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.

    Source:Hussin X
    Published:18 Mar 2009
    7.5
    High

    CVE-2008-6484

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attackers to execute arbitrary SQL commands via the user field.

    Source:InjEctOr5
    Published:18 Mar 2009
    7.5
    High

    CVE-2008-6483

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:NoGe
    Published:18 Mar 2009
    6.8
    Medium

    CVE-2008-6482

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter.

    Source:NoGe
    Published:18 Mar 2009
    7.5
    High

    CVE-2008-6481

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

    Source:DarkMatter Crew
    Published:17 Mar 2009
    6.8
    Medium

    CVE-2008-6479

    Last Modified: 12 Feb 2014

    Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd.

    Source:poplix
    Published:16 Mar 2009
    6.8
    Medium

    CVE-2008-6478

    Last Modified: 12 Feb 2014

    Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to create and delete arbitrary files as the administrator via a link or IMG tag to (1) create-file and (2) list-control in vz/cp/vzdir/infrman/envs/files/; or modify system configuration via the path parameter to vz/cp/vzdir/infrman/envs/files/index.

    Source:poplix
    Published:16 Mar 2009
    7.5
    High

    CVE-2008-6477

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:Lidloses_Auge
    Published:16 Mar 2009
    4.3
    Medium

    CVE-2008-6476

    Last Modified: 15 Apr 2014

    Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:sk
    Published:16 Mar 2009
    7.5
    High

    CVE-2008-6475

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.

    Source:EgiX
    Published:16 Mar 2009
    6.4
    Medium

    CVE-2008-6473

    Last Modified: 23 Apr 2026

    _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.

    Source:Virangar Security
    Published:16 Mar 2009
    7.5
    High

    CVE-2008-6471

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a show action.

    Source:Egypt Coder
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6469

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Source:r45c4l
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6468

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action.

    Source:ZoRLu
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6467

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.

    Source:Stack
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6466

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action.

    Source:boom3rang
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6464

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:0x90
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6454

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.

    Source:Hussin X
    Published:13 Mar 2009
    4.3
    Medium

    CVE-2008-6453

    Last Modified: 30 Nov 2016

    Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Source:Stack
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6452

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JEEN HACKER TEAM
    Published:13 Mar 2009
    7.5
    High

    CVE-2008-6451

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE-2005-3509.

    Source:r45c4l
    Published:13 Mar 2009
    9.3
    Critical

    CVE-2008-6447

    Last Modified: 23 Apr 2026

    Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.

    Source:Francis Provencher
    Published:9 Mar 2009
    7.5
    High

    CVE-2008-6446

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter.

    Source:CWH Underground
    Published:9 Mar 2009
    7.5
    High

    CVE-2008-6443

    Last Modified: 6 Mar 2014

    SQL injection vulnerability in forum_duzen.php in phpKF allows remote attackers to execute arbitrary SQL commands via the fno parameter.

    Source:U238
    Published:9 Mar 2009
    5.8
    Medium

    CVE-2008-6442

    Last Modified: 5 Mar 2014

    Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Symantec
    Published:9 Mar 2009
    4.3
    Medium

    CVE-2008-6439

    Last Modified: 22 Feb 2014

    Cross-site scripting (XSS) vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Source:Ali Jasbi
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6438

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.

    Source:ZoRLu
    Published:6 Mar 2009
    4.3
    Medium

    CVE-2008-6437

    Last Modified: 22 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.

    Source:tan_prathan
    Published:6 Mar 2009
    4.3
    Medium

    CVE-2008-6435

    Last Modified: 22 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in phpSQLiteCMS 1 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[home], (2) lang[admin_menu], and (3) lang[admin_menu_page_overview] parameters to cms/includes/header.inc.php; and the (4) lang[login_username] and (5) lang[login_password] parameters to cms/includes/login.inc.php.

    Source:CWH Underground
    Published:6 Mar 2009
    4.3
    Medium

    CVE-2008-6431

    Last Modified: 23 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to newtem/footer/bsd01footer.php, and the (4) topads and (5) myplugin parameters to newtem/header/bsd01header.php.

    Source:CWH Underground
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6430

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Source:His0k4
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6429

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.

    Source:His0k4
    Published:6 Mar 2009
    6.8
    Medium

    CVE-2008-6427

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:security fears team
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6425

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.

    Source:JosS
    Published:6 Mar 2009
    5
    Medium

    CVE-2008-6423

    Last Modified: 1 Dec 2016

    Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.

    Source:mozi
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6422

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php.

    Source:Mr.SQL
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6421

    Last Modified: 1 Dec 2016

    PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:vBmad
    Published:6 Mar 2009
    5
    Medium

    CVE-2008-6420

    Last Modified: 1 Dec 2016

    Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php.

    Source:DeAr Ev!L
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6419

    Last Modified: 1 Dec 2016

    Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_profile_download.php, and the (3) catid parameter to social_forum_subcategories.php.

    Source:DeAr Ev!L
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6418

    Last Modified: 24 Feb 2014

    SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.

    Source:Charles Vaughn
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6414

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Source:GoLd_M
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6411

    Last Modified: 23 Apr 2026

    Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1.

    Source:Stack
    Published:6 Mar 2009