7.5
    High

    CVE-2008-6075

    Last Modified: 25 Mar 2014

    SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL commands via the kid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CyberGrup Lojistik
    Published:6 Feb 2009
    5.1
    Medium

    CVE-2008-6074

    Last Modified: 2 Jan 2017

    Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter.

    Source:Pepelux
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6068

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.

    Source:His0k4
    Published:6 Feb 2009
    7.5
    High

    CVE-2008-6066

    Last Modified: 13 Mar 2014

    Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules.php, (2) ManagerResource.class.php, (3) ManagerRightsResource.class.php, (4) RegForm.class.php, (5) RegResource.class.php, and (6) RegRightsResource.class.php in classes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Rakesh S
    Published:5 Feb 2009
    5.1
    Medium

    CVE-2008-6065

    Last Modified: 24 Mar 2014

    Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file through UTL_FILE operations, a related issue to CVE-2006-7141.

    Source:Paul M. Wright
    Published:5 Feb 2009
    7.5
    High

    CVE-2008-6064

    Last Modified: 10 Nov 2016

    Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the cat parameter to agenda/index.php, and unspecified other vectors.

    Source:MhZ91
    Published:5 Feb 2009
    4.3
    Medium

    CVE-2008-6061

    Last Modified: 16 Jan 2014

    Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary additional SWF content via a URL in the csPreloader parameter.

    Source:Rich Cannings
    Published:5 Feb 2009
    4.3
    Medium

    CVE-2008-6060

    Last Modified: 16 Jan 2014

    Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter.

    Source:Rich Cannings
    Published:5 Feb 2009
    5
    Medium

    CVE-2008-6057

    Last Modified: 5 Sept 2016

    Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

    Source:Cold Zero
    Published:4 Feb 2009
    7.5
    High

    CVE-2008-6050

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php.

    Source:InjEctOr5
    Published:4 Feb 2009
    Low

    CVE-2008-6049

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.php in TinyMCE 2.0.1 allows remote attackers to execute arbitrary SQL commands via the menuID parameter. NOTE: CVE and multiple reliable third parties dispute this issue, since TinyMCE does not contain index.php or any PHP code. This may be an issue in a product that has integrated TinyMCE

    Source:AnGeL25dZ
    Published:4 Feb 2009
    6.8
    Medium

    CVE-2008-6045

    Last Modified: 21 Mar 2014

    Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XTCsid parameter.

    Source:David Vieira-Kurz
    Published:3 Feb 2009
    4.3
    Medium

    CVE-2008-6044

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in advanced_search_result.php in xt:Commerce 3.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Source:David Vieira-Kurz
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6043

    Last Modified: 20 Mar 2014

    Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL commands via the (1) order_field and (2) order_type parameters to categories.php and unspecified other components. NOTE: some of these details are obtained from third party information.

    Source:Jan Van Niekerk
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6042

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.

    Source:Encrypt3d.M!nd
    Published:3 Feb 2009
    6.8
    Medium

    CVE-2008-6039

    Last Modified: 21 Mar 2014

    Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Source:David Vieira-Kurz
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6038

    Last Modified: 21 Mar 2014

    SQL injection vulnerability in index.php in MapCal 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an editevent action, possibly related to dsp_editevent.php.

    Source:0x90
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6037

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the v parameter.

    Source:Hussin X
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6036

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mj_config[src_path] parameter.

    Source:dun
    Published:3 Feb 2009
    4.3
    Medium

    CVE-2008-6034

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the atkaction parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Rohit Bansal
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6033

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:d3v1l
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6032

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Stack
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6031

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported that 2.34 is also vulnerable.

    Source:d3v1l
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6030

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL commands via (1) the job parameter to index.php in the search module or (2) the news_id parameter to index.php.

    Source:Encrypt3d.M!nd
    Published:3 Feb 2009
    6.8
    Medium

    CVE-2008-6029

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:~!Dok_tOR!~
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6028

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter in a subject action.

    Source:d3v1l
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6026

    Last Modified: 21 Mar 2014

    SQL injection vulnerability in tienda.php in BlueCUBE CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r45c4l
    Published:3 Feb 2009
    6.8
    Medium

    CVE-2008-6025

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in scr/form.php in openElec 3.01 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the obj parameter.

    Source:dun
    Published:3 Feb 2009
    7.5
    High

    CVE-2008-6023

    Last Modified: 20 Dec 2016

    PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the xnova_root_path parameter.

    Source:NuclearHaxor
    Published:2 Feb 2009
    7.5
    High

    CVE-2008-6022

    Last Modified: 20 Dec 2016

    PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the ugamela_root_path parameter.

    Source:NuclearHaxor
    Published:2 Feb 2009
    7.5
    High

    CVE-2008-6019

    Last Modified: 3 Apr 2014

    SQL injection vulnerability in index.php in EACOMM DO-CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:crash over
    Published:2 Feb 2009
    6.8
    Medium

    CVE-2008-6018

    Last Modified: 5 Jan 2017

    Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

    Source:Piker
    Published:2 Feb 2009
    7.5
    High

    CVE-2008-6017

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands via the idp parameter.

    Source:boom3rang
    Published:2 Feb 2009
    7.5
    High

    CVE-2008-6016

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3952. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:SuB-ZeRo
    Published:30 Jan 2009
    7.5
    High

    CVE-2008-6014

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in scripts/links.php in Rianxosencabos CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ka0x
    Published:30 Jan 2009
    4.3
    Medium

    CVE-2008-6012

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a viewEntry action.

    Source:Pepelux
    Published:30 Jan 2009
    7.5
    High

    CVE-2008-6011

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Source:Stack
    Published:30 Jan 2009
    5
    Medium

    CVE-2008-6010

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php.

    Source:SirGod
    Published:30 Jan 2009
    7.5
    High

    CVE-2008-6009

    Last Modified: 23 Apr 2026

    SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.

    Source:Stack
    Published:30 Jan 2009
    7.5
    High

    CVE-2008-6007

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in view_group.php in QuidaScript BookMarks Favourites Script (APB) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:30 Jan 2009
    7.5
    High

    CVE-2008-6006

    Last Modified: 23 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to execute arbitrary PHP code via a URL in the minsoft_path parameter to (1) utdb_access.php and (2) utgn_message.php in utility/.

    Source:DaRkLiFe
    Published:30 Jan 2009
    4.3
    Medium

    CVE-2008-6004

    Last Modified: 28 Nov 2016

    Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter.

    Source:InjEctOr5
    Published:28 Jan 2009
    7.5
    High

    CVE-2008-6003

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter.

    Source:InjEctOr5
    Published:28 Jan 2009
    7.1
    High

    CVE-2008-6002

    Last Modified: 23 Dec 2016

    Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation parameter.

    Source:GoLd_M
    Published:28 Jan 2009
    7.5
    High

    CVE-2008-6001

    Last Modified: 23 Dec 2016

    index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field, and a final :sysop:0 string.

    Source:Pepelux
    Published:28 Jan 2009
    6
    Medium

    CVE-2008-5998

    Last Modified: 21 Mar 2014

    Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.

    Source:Justin C. Klein Keane
    Published:28 Jan 2009
    7.8
    High

    CVE-2008-5997

    Last Modified: 21 Mar 2014

    Absolute path traversal vulnerability in admin/fileKontrola/browser.asp in Omnicom Content Platform (OCP) 2.0 allows remote attackers to list arbitrary directories via a full pathname in the root parameter.

    Source:AlbaniaN-[H]
    Published:28 Jan 2009
    7.5
    High

    CVE-2008-5993

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in image.php in Barcode Generator 1D (barcodegen) 2.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the code parameter.

    Source:dun
    Published:28 Jan 2009
    7.5
    High

    CVE-2008-5992

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL commands via the KayitNo parameter to (1) diger.php and (2) sayfalar.php.

    Source:ZoRLu
    Published:28 Jan 2009
    7.5
    High

    CVE-2008-5991

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the doc parameter.

    Source:dun
    Published:28 Jan 2009