7.5
    High

    CVE-2008-6155

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:InjEctOr5
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.

    Source:InjEctOr5
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6153

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.

    Source:AlpHaNiX
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6152

    Last Modified: 10 Jan 2017

    SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: this was originally reported for Lawyer Portal, which does not have a deptdisplay.asp file.

    Source:Osmanizim
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6151

    Last Modified: 10 Jan 2017

    SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:Osmanizim
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6150

    Last Modified: 10 Jan 2017

    SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:S.W.A.T.
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6149

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cagtegory parameter in a story_lists action to index.php.

    Source:boom3rang
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6148

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in the Live Ticker (com_liveticker) module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a viewticker action to index.php.

    Source:boom3rang
    Published:16 Feb 2009
    5
    Medium

    CVE-2008-6147

    Last Modified: 23 Apr 2026

    ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/8690.mdb or (2) data/8690BAK.mdb.

    Source:Cyber.Zer0
    Published:16 Feb 2009
    6.8
    Medium

    CVE-2008-6146

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.

    Source:StAkeR
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6143

    Last Modified: 23 Apr 2026

    OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie.

    Source:Osirys
    Published:16 Feb 2009
    7.5
    High

    CVE-2008-6142

    Last Modified: 23 Jan 2017

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.x versions, allow remote attackers to execute arbitrary SQL commands via (1) the checkuser parameter (aka username field), or (2) the checkpass parameter (aka password field), to admin/index.php.

    Source:S.W.A.T.
    Published:16 Feb 2009
    5
    Medium

    CVE-2008-6139

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in faqsupport/wce.download.php in WebBiscuits Modules Controller 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.

    Source:GoLd_M
    Published:14 Feb 2009
    7.5
    High

    CVE-2008-6138

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.

    Source:GoLd_M
    Published:14 Feb 2009
    7.5
    High

    CVE-2008-6133

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3942.

    Source:Hussin X
    Published:13 Feb 2009
    6.8
    Medium

    CVE-2008-6132

    Last Modified: 23 Dec 2016

    Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via the start_date parameter.

    Source:Metasploit
    Published:13 Feb 2009
    5
    Medium

    CVE-2008-6126

    Last Modified: 15 Dec 2016

    Multiple directory traversal vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to download.php and the (2) page parameter to index.php, a different vector than CVE-2008-3589.

    Source:SirGod
    Published:13 Feb 2009
    7.8
    High

    CVE-2008-6122

    Last Modified: 30 Mar 2014

    The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question mark ("?").

    Source:sr.
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6119

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:BeyazKurt
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6118

    Last Modified: 23 Apr 2026

    win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.

    Source:x0r
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6117

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_id parameter in a results action.

    Source:ZoRLu
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6116

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php.

    Source:Ded MustD!e
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6115

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.

    Source:snakespc
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6114

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitrary SQL commands via the product parameter.

    Source:NoGe
    Published:11 Feb 2009
    5
    Medium

    CVE-2008-6112

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) main.php and (2) template.php in ringtones/.

    Source:b3hz4d
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6111

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in blog.php in NetArt Media Vlog System 1.1 allows remote attackers to execute arbitrary SQL commands via the note parameter.

    Source:Mr.SQL
    Published:11 Feb 2009
    7.5
    High

    CVE-2008-6104

    Last Modified: 11 Apr 2014

    SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via the eventid parameter to admin/index.php.

    Source:r45c4l
    Published:10 Feb 2009
    6.8
    Medium

    CVE-2008-6103

    Last Modified: 23 Mar 2014

    PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.

    Source:Lo$er
    Published:10 Feb 2009
    7.5
    High

    CVE-2008-6102

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in ratelink.php in Link Trader Script allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.

    Source:Hussin X
    Published:10 Feb 2009
    7.5
    High

    CVE-2008-6101

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.

    Source:Hussin X
    Published:10 Feb 2009
    6.8
    Medium

    CVE-2008-6100

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to (a) RSS1.php and (b) RSS2.php in misc/; and the (2) SubID parameter to (c) misc/RSS5.php.

    Source:~!Dok_tOR!~
    Published:10 Feb 2009
    7.5
    High

    CVE-2008-6099

    Last Modified: 23 Dec 2016

    PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_op parameter.

    Source:Kad
    Published:10 Feb 2009
    4.3
    Medium

    CVE-2008-6097

    Last Modified: 23 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to index.php/Edit/Main/Home, (3) to parameter to index.php/Special/Main/WhatLinksHere, (4) user parameter to index.php/Special/Main/UserEdits, and (5) the PATH_INFO to index.php.

    Source:Omer Singer
    Published:9 Feb 2009
    4.3
    Medium

    CVE-2008-6094

    Last Modified: 23 Mar 2014

    Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject arbitrary web script or HTML via the ni.smessage parameter.

    Source:teuquooch1seero
    Published:9 Feb 2009
    6.8
    Medium

    CVE-2008-6093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) file_id parameter in a detailansicht action and the (2) kategorie parameter in a kategorien action.

    Source:~!Dok_tOR!~
    Published:9 Feb 2009
    7.5
    High

    CVE-2008-6092

    Last Modified: 23 Apr 2026

    phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.

    Source:Crackers_Child
    Published:9 Feb 2009
    6.8
    Medium

    CVE-2008-6091

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter.

    Source:~!Dok_tOR!~
    Published:9 Feb 2009
    4.3
    Medium

    CVE-2008-6090

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitrary local files via a .. (dot dot) in the dir parameter in a view action.

    Source:JosS
    Published:6 Feb 2009
    5
    Medium

    CVE-2008-6089

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a download action.

    Source:JosS
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6088

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.

    Source:rsauron
    Published:6 Feb 2009
    4.3
    Medium

    CVE-2008-6087

    Last Modified: 26 Dec 2016

    Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Source:BackDoor
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6086

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-3355.

    Source:BackDoor
    Published:6 Feb 2009
    6.8
    Medium

    CVE-2008-6084

    Last Modified: 2 Jan 2017

    Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

    Source:x0r
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6083

    Last Modified: 2 Jan 2017

    Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:Pepelux
    Published:6 Feb 2009
    5
    Medium

    CVE-2008-6082

    Last Modified: 27 Sept 2016

    Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command.

    Source:dmnt
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6081

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:6 Feb 2009
    5
    Medium

    CVE-2008-6080

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Vrs-hCk
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6078

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a pms action to index.php.

    Source:StAkeR
    Published:6 Feb 2009
    6.5
    Medium

    CVE-2008-6077

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to execute arbitrary SQL commands via the colpick parameter in a singleread action.

    Source:Xianur0
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6076

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:H!tm@N
    Published:6 Feb 2009