7.5
    High

    CVE-2008-6410

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.

    Source:dun
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6409

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.

    Source:ThE TiGeR
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6408

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in the framefile parameter.

    Source:GoLd_M
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6407

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the framefile parameter.

    Source:GoLd_M
    Published:6 Mar 2009
    4.3
    Medium

    CVE-2008-6406

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in admin.php in DataLife Engine (DLE) 7.2 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:Hadi Kiamarsi
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6405

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Hussin X
    Published:6 Mar 2009
    4.3
    Medium

    CVE-2008-6404

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter.

    Source:DigiTrust Group
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6403

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpl_dir parameter.

    Source:dun
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6402

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in hu/modules/reg-new/modstart.php in Sofi WebGui 0.6.3 PRE and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mod_dir parameter.

    Source:dun
    Published:6 Mar 2009
    7.5
    High

    CVE-2008-6401

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Source:d3v1l
    Published:6 Mar 2009
    4.3
    Medium

    CVE-2008-6396

    Last Modified: 18 Mar 2014

    Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

    Source:Xc0re
    Published:4 Mar 2009
    7.5
    High

    CVE-2008-6394

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.

    Source:GulfTech Security
    Published:4 Mar 2009
    10
    Critical

    CVE-2008-6393

    Last Modified: 23 Apr 2026

    PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

    Source:Sha0
    Published:29 Dec 2008
    7.5
    High

    CVE-2008-6392

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Pouya_Server
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6391

    Last Modified: 1 Apr 2014

    SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter).

    Source:Pouya_Server
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6390

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Cyber-Zone
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6389

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.

    Source:b3hz4d
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6388

    Last Modified: 4 Jan 2017

    Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb.

    Source:CoBRa_21
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6387

    Last Modified: 4 Jan 2017

    Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.

    Source:Cyber-Zone
    Published:2 Mar 2009
    4.3
    Medium

    CVE-2008-6386

    Last Modified: 4 Jan 2017

    Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Pouya_Server
    Published:2 Mar 2009
    4.3
    Medium

    CVE-2008-6385

    Last Modified: 1 Apr 2014

    Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Source:Pouya_Server
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6382

    Last Modified: 4 Jan 2017

    ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb.

    Source:CWH Underground
    Published:2 Mar 2009
    4.6
    Medium

    CVE-2008-6381

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.

    Source:CWH Underground
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6380

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

    Source:Cyber-Zone
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6379

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:R3d-D3V!L
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6378

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:R3d-D3V!L
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6377

    Last Modified: 4 Jan 2017

    PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.

    Source:NoGe
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6376

    Last Modified: 1 Apr 2014

    SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).

    Source:Pouya_Server
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6374

    Last Modified: 6 Jan 2017

    CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.

    Source:AlpHaNiX
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6372

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: some of these details are obtained from third party information.

    Source:Stack
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6371

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter).

    Source:Cyber-Zone
    Published:2 Mar 2009
    4.3
    Medium

    CVE-2008-6370

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to inject arbitrary web script or HTML via the DisplayFormat parameter.

    Source:Pouya_Server
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6369

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.

    Source:Pouya_Server
    Published:2 Mar 2009
    8.5
    High

    CVE-2008-6367

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in Member_images/.

    Source:InjEctOr5
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6366

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, possibly related to the uname and pass parameters to logon_process.jsp. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6365

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password, related to the uname or pass parameters to logon.jsp or logon_processing.jsp. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6364

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:2 Mar 2009
    9.3
    Critical

    CVE-2008-6363

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary code via a crafted .cct file. NOTE: some of these details are obtained from third party information.

    Source:Cnaph
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6362

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ViRuS_HaCkErS
    Published:2 Mar 2009
    6.8
    Medium

    CVE-2008-6361

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter.

    Source:x0r
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6358

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:InjEctOr5
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6357

    Last Modified: 5 Jan 2017

    MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to mycal.mdb.

    Source:CoBRa_21
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6356

    Last Modified: 23 Apr 2026

    evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to (1) evcal.mdb and (2) evcal97.mdb.

    Source:Cyber-Zone
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6355

    Last Modified: 23 Apr 2026

    The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2Protect.mdb.

    Source:AlpHaNiX
    Published:2 Mar 2009
    5
    Medium

    CVE-2008-6354

    Last Modified: 23 Apr 2026

    The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb.

    Source:AlpHaNiX
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6353

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cha parameter.

    Source:Khashayar Fereidani
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6352

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.

    Source:XaDoS
    Published:2 Mar 2009
    4.3
    Medium

    CVE-2008-6351

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter.

    Source:TR-ShaRk
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6350

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter.

    Source:TR-ShaRk
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6349

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:G4N0K
    Published:2 Mar 2009