6.8
    Medium

    CVE-2008-5990

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sitecode parameter to connect/index.php.

    Source:dun
    Published:28 Jan 2009
    6.8
    Medium

    CVE-2008-5989

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

    Source:dun
    Published:28 Jan 2009
    7.5
    High

    CVE-2008-5988

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in scripts/recruit_details.php in Jadu CMS for Government allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r45c4l
    Published:28 Jan 2009
    5
    Medium

    CVE-2008-5981

    Last Modified: 4 Jan 2017

    PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) poll.mdb or (2) poll97.mdb.

    Source:AlpHaNiX
    Published:27 Jan 2009
    5
    Medium

    CVE-2008-5980

    Last Modified: 5 Sept 2016

    Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.

    Source:Pouya_Server
    Published:27 Jan 2009
    4.3
    Medium

    CVE-2008-5979

    Last Modified: 5 Sept 2016

    Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.

    Source:Pouya_Server
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5978

    Last Modified: 31 Mar 2014

    Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.

    Source:Charalambous Glafkos
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5977

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

    Source:Pouya_Server
    Published:27 Jan 2009
    4.3
    Medium

    CVE-2008-5976

    Last Modified: 6 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field.

    Source:Pouya_Server
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5975

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:R3d-D3V!L
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5974

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.

    Source:R3d-D3V!L
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5973

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Source:R3d-D3V!L
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5972

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:AlpHaNiX
    Published:27 Jan 2009
    4.3
    Medium

    CVE-2008-5971

    Last Modified: 1 Apr 2014

    Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.

    Source:d3b4g
    Published:27 Jan 2009
    6.5
    Medium

    CVE-2008-5970

    Last Modified: 1 Apr 2014

    SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Source:d3b4g
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5969

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:w4rl0ck
    Published:27 Jan 2009
    7.5
    High

    CVE-2008-5968

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292.

    Source:EgiX
    Published:26 Jan 2009
    7.5
    High

    CVE-2008-5967

    Last Modified: 23 Apr 2026

    admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

    Source:EgiX
    Published:26 Jan 2009
    7.5
    High

    CVE-2008-5966

    Last Modified: 14 Nov 2016

    globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.

    Source:StAkeR
    Published:26 Jan 2009
    5
    Medium

    CVE-2008-5965

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot) in the page parameter.

    Source:JosS
    Published:26 Jan 2009
    10
    Critical

    CVE-2008-5963

    Last Modified: 6 Jan 2017

    Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter.

    Source:dun
    Published:23 Jan 2009
    6.8
    Medium

    CVE-2008-5962

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the objectname parameter.

    Source:dun
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5959

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or (2) password parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5958

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp.

    Source:R3d-D3V!L
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5957

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php.

    Source:Khashayar Fereidani
    Published:23 Jan 2009
    5
    Medium

    CVE-2008-5956

    Last Modified: 23 Apr 2026

    Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request to connect.inc.

    Source:CWH Underground
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5955

    Last Modified: 1 Apr 2014

    SQL injection vulnerability in show.php in Wbstreet (aka PHPSTREET Webboard) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:23 Jan 2009
    6.8
    Medium

    CVE-2008-5954

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a login action to an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CWH Underground
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5953

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to the default URI.

    Source:CWH Underground
    Published:23 Jan 2009
    6
    Medium

    CVE-2008-5952

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a vtech action to the default URI.

    Source:CWH Underground
    Published:23 Jan 2009
    5
    Medium

    CVE-2008-5951

    Last Modified: 23 Apr 2026

    ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb.

    Source:ZoRLu
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5950

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter.

    Source:ZoRLu
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5949

    Last Modified: 4 Jan 2017

    Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php; (2) handle/proxy.php; (3) header.php, (4) include.php, and (5) workspace.php in includes/; and (6) plugins/RSS/files/rss.php.

    Source:cOndemned
    Published:23 Jan 2009
    7.5
    High

    CVE-2008-5948

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.

    Source:dun
    Published:23 Jan 2009
    6.8
    Medium

    CVE-2008-5947

    Last Modified: 14 Mar 2014

    PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in the cfgIncludeDirectory parameter.

    Source:CraCkEr
    Published:22 Jan 2009
    7.5
    High

    CVE-2008-5946

    Last Modified: 14 Mar 2014

    SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Source:Rake
    Published:22 Jan 2009
    7.5
    High

    CVE-2008-5945

    Last Modified: 14 Mar 2014

    Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ciph3r
    Published:22 Jan 2009
    2.6
    Low

    CVE-2008-5944

    Last Modified: 14 Mar 2014

    Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter.

    Source:CraCkEr
    Published:22 Jan 2009
    7.5
    High

    CVE-2008-5943

    Last Modified: 14 Mar 2014

    Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to (1) admin_modules.php and (2) modules.php.

    Source:CraCkEr
    Published:22 Jan 2009
    4.3
    Medium

    CVE-2008-5939

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, possibly related to snippet.ditto.php. NOTE: some sources list the id parameter as being affected, but this is probably incorrect based on the original disclosure.

    Source:RoMaNcYxHaCkEr
    Published:22 Jan 2009
    6.8
    Medium

    CVE-2008-5938

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the reflect_base parameter.

    Source:RoMaNcYxHaCkEr
    Published:22 Jan 2009
    7.8
    High

    CVE-2008-5937

    Last Modified: 5 Oct 2017

    AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values.

    Source:suN8Hclf
    Published:22 Jan 2009
    5
    Medium

    CVE-2008-5936

    Last Modified: 2 Jan 2017

    front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parameter.

    Source:GoLd_M
    Published:22 Jan 2009
    7.5
    High

    CVE-2008-5934

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via the id_sezione parameter.

    Source:XaDoS
    Published:21 Jan 2009
    4.3
    Medium

    CVE-2008-5933

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka the input field for the cerca action) or (2) the id_oggetto parameter. NOTE: some of these details are obtained from third party information.

    Source:XaDoS
    Published:21 Jan 2009
    5
    Medium

    CVE-2008-5932

    Last Modified: 5 Jan 2017

    CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information.

    Source:Ghost Hacker
    Published:21 Jan 2009
    5
    Medium

    CVE-2008-5931

    Last Modified: 23 Apr 2026

    The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information.

    Source:Pouya_Server
    Published:21 Jan 2009
    7.5
    High

    CVE-2008-5930

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute arbitrary SQL commands via the BlogID parameter.

    Source:Pouya_Server
    Published:21 Jan 2009
    5
    Medium

    CVE-2008-5929

    Last Modified: 23 Apr 2026

    VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the password via a direct request for database/shopping650.mdb. NOTE: some of these details are obtained from third party information.

    Source:Dxil
    Published:21 Jan 2009
    7.5
    High

    CVE-2008-5928

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in redir.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:nuclear
    Published:21 Jan 2009