7.5
    High

    CVE-2008-6348

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.

    Source:InjEctOr5
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6347

    Last Modified: 2 Jan 2017

    PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:NoGe
    Published:2 Mar 2009
    7.5
    High

    CVE-2008-6345

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to indes.php. NOTE: some of these details are obtained from third party information.

    Source:StAkeR
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6337

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the job_id parameter in a jobshow action to index.php.

    Source:boom3rang
    Published:27 Feb 2009
    4.3
    Medium

    CVE-2008-6336

    Last Modified: 5 Jan 2017

    Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to read arbitrary local files via directory traversal sequences in the filename parameter.

    Source:SirGod
    Published:27 Feb 2009
    7.8
    High

    CVE-2008-6335

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Cold Zero
    Published:27 Feb 2009
    7.8
    High

    CVE-2008-6334

    Last Modified: 5 Jan 2017

    Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Cold Zero
    Published:27 Feb 2009
    6.8
    Medium

    CVE-2008-6333

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:Piker
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6332

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Source:d3b4g
    Published:27 Feb 2009
    6.5
    Medium

    CVE-2008-6330

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the send parameter in a notes action.

    Source:cOndemned
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6329

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters, as reachable from Employee/emp_login.asp. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6328

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6327

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter, a different vector than CVE-2008-6312.

    Source:Osirys
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6326

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:d3b4g
    Published:27 Feb 2009
    4.3
    Medium

    CVE-2008-6325

    Last Modified: 31 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php, (5) radio parameter to showcategory.php, (6) msg parameter to admin/adminhome.php, and (7) msg parameter to admin/index.php. NOTE: a different signinform.php file is already covered by CVE-2008-6306.

    Source:Pouya_Server
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6324

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

    Source:AlpHaNiX
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6323

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

    Source:AlpHaNiX
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6322

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.

    Source:AlpHaNiX
    Published:27 Feb 2009
    5
    Medium

    CVE-2008-6321

    Last Modified: 23 Apr 2026

    CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via a direct request.

    Source:AlpHaNiX
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6320

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands via the Category parameter in a ViewCategory action.

    Source:AlpHaNiX
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6319

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL commands via the calid parameter.

    Source:AlpHaNiX
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6318

    Last Modified: 4 Jan 2017

    PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter, a different vector than CVE-2008-6317.

    Source:CoBRa_21
    Published:27 Feb 2009
    6.8
    Medium

    CVE-2008-6317

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf[lang] parameter, a different issue than CVE-2008-6318. NOTE: this might be the same issue as CVE-2008-6316.

    Source:ZoRLu
    Published:27 Feb 2009
    6.8
    Medium

    CVE-2008-6316

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter, a different issue than CVE-2008-6316 and a different vector than CVE-2008-6318.

    Source:ZoRLu
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6315

    Last Modified: 27 Oct 2016

    PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to execute arbitrary PHP code via a URL in the confdir parameter, a different issue than CVE-2008-6316.

    Source:ZoRLu
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6314

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

    Source:StAkeR
    Published:27 Feb 2009
    6.8
    Medium

    CVE-2008-6313

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in addedit-render.php in phpAddEdit 1.3, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a URL in the editform parameter. NOTE: PHP remote file inclusion attacks are also likely.

    Source:nuclear
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6312

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Osirys
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6311

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.

    Source:CWH Underground
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6310

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.

    Source:TR-ShaRk
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6309

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands via the f[password] parameter. NOTE: some of these details are obtained from third party information.

    Source:TR-ShaRk
    Published:27 Feb 2009
    5.1
    Medium

    CVE-2008-6308

    Last Modified: 6 Jan 2017

    Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_user[language] parameter to (1) functions_navlinks.php, (2) header_new_messages.php, (3) profile_send.php, and (4) viewtopic_PM-link.php in include/pms/.

    Source:StAkeR
    Published:27 Feb 2009
    7.5
    High

    CVE-2008-6307

    Last Modified: 23 Apr 2026

    E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin."

    Source:x0r
    Published:26 Feb 2009
    4.3
    Medium

    CVE-2008-6306

    Last Modified: 30 Mar 2014

    Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Vahid Ezraeil
    Published:26 Feb 2009
    6.8
    Medium

    CVE-2008-6305

    Last Modified: 3 Jan 2017

    PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the API_HOME_DIR parameter.

    Source:Ghost Hacker
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6303

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in tourview.php in ToursManager allows remote attackers to execute arbitrary SQL commands via the tourid parameter.

    Source:XaDoS
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6302

    Last Modified: 23 Apr 2026

    TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php.

    Source:G4N0K
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6301

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.

    Source:StAkeR
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6300

    Last Modified: 23 Apr 2026

    Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass cookies to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Virangar Security
    Published:26 Feb 2009
    4.3
    Medium

    CVE-2008-6297

    Last Modified: 28 Mar 2014

    Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script or HTML via the (1) domain and (2) d1 parameters.

    Source:Lostmon
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6296

    Last Modified: 23 Apr 2026

    admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

    Source:JosS
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6294

    Last Modified: 23 Apr 2026

    admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."

    Source:x0r
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6293

    Last Modified: 23 Apr 2026

    admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."

    Source:x0r
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6292

    Last Modified: 23 Apr 2026

    Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) right_cookie to "1," and (3) id_cookie to "1."

    Source:x0r
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6291

    Last Modified: 23 Apr 2026

    Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".

    Source:Hakxer
    Published:26 Feb 2009
    6.8
    Medium

    CVE-2008-6290

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includefile.php in nicLOR Sito, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the page_file parameter.

    Source:StAkeR
    Published:26 Feb 2009
    7.5
    High

    CVE-2008-6289

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in cityview.php in Tours Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the cityid parameter.

    Source:G4N0K
    Published:26 Feb 2009
    7.8
    High

    CVE-2008-6288

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Dyshoo
    Published:25 Feb 2009
    7.5
    High

    CVE-2008-6287

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Broadcast Machine 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) MySQLController.php, (2) SQLController.php, (3) SetupController.php, (4) VideoController.php, and (5) ViewController.php in controllers/.

    Source:NoGe
    Published:25 Feb 2009
    7.5
    High

    CVE-2008-6286

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute arbitrary SQL commands via (1) the email parameter (aka username or E-mail field), or (2) the password parameter (aka password field), to (a) Subscriber.asp or (b) start.asp. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:25 Feb 2009