7.5
    High

    CVE-2008-5851

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.

    Source:Piker
    Published:6 Jan 2009
    2.6
    Low

    CVE-2008-5847

    Last Modified: 23 Apr 2026

    Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.

    Source:fuzion
    Published:5 Jan 2009
    7.5
    High

    CVE-2008-5841

    Last Modified: 11 Oct 2010

    Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.

    Source:Sweet
    Published:5 Jan 2009
    7.5
    High

    CVE-2008-5840

    Last Modified: 23 Apr 2026

    PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.

    Source:Stack
    Published:5 Jan 2009
    9.3
    Critical

    CVE-2008-5839

    Last Modified: 21 Mar 2014

    Buffer overflow in Foxmail 6.5 allows remote attackers to execute arbitrary code via a long mailto URI in the HREF attribute of an A element.

    Source:sebug
    Published:5 Jan 2009
    7.5
    High

    CVE-2008-5838

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Mormoroth
    Published:5 Jan 2009
    6.8
    Medium

    CVE-2008-5824

    Last Modified: 24 Jan 2017

    Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WAV file.

    Source:Anton Khirnov
    Published:30 Dec 2008
    5
    Medium

    CVE-2008-5821

    Last Modified: 4 Apr 2014

    Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.

    Source:Jeremy Brown
    Published:2 Jan 2009
    7.5
    High

    CVE-2008-5820

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Source:Virangar Security
    Published:2 Jan 2009
    6.8
    Medium

    CVE-2008-5819

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in eDNews_archive.php in eDreamers eDNews 2, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lg parameter. NOTE: some of these details are obtained from third party information.

    Source:GoLd_M
    Published:2 Jan 2009
    6.8
    Medium

    CVE-2008-5818

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lg parameter. NOTE: some of these details are obtained from third party information.

    Source:GoLd_M
    Published:2 Jan 2009
    6.8
    Medium

    CVE-2008-5817

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in a sign_in action.

    Source:AnGeL25dZ
    Published:2 Jan 2009
    7.5
    High

    CVE-2008-5816

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ref_id parameter.

    Source:Lidloses_Auge
    Published:2 Jan 2009
    7.5
    High

    CVE-2008-5815

    Last Modified: 10 Jan 2017

    SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mr.SQL
    Published:2 Jan 2009
    7.5
    High

    CVE-2008-5811

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php.

    Source:XaDoS
    Published:2 Jan 2009
    7.5
    High

    CVE-2008-5806

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5805

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.

    Source:ZoRLu
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5804

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.

    Source:Hussin X
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5803

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5802

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:Stack
    Published:31 Dec 2008
    5
    Medium

    CVE-2008-5794

    Last Modified: 26 Dec 2010

    Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

    Source:cOndemned
    Published:31 Dec 2008
    6.8
    Medium

    CVE-2008-5793

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.

    Source:NoGe
    Published:31 Dec 2008
    6.8
    Medium

    CVE-2008-5792

    Last Modified: 2 Jan 2017

    PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: the researcher also points out the analogous directory traversal issue.

    Source:BugReport.IR
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5790

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.

    Source:NoGe
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5789

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.

    Source:NoGe
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5788

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:TR-ShaRk
    Published:31 Dec 2008
    5.4
    Medium

    CVE-2008-5787

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction with a show action.

    Source:Khashayar Fereidani
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5785

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Source:d3b4g
    Published:31 Dec 2008
    9.8
    Critical

    CVE-2008-5784

    Last Modified: 23 Apr 2026

    V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

    Source:Cyber-Zone
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5783

    Last Modified: 23 Apr 2026

    admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

    Source:Cyber-Zone
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5782

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Source:Hussin X
    Published:31 Dec 2008
    7.5
    High

    CVE-2008-5781

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in right.php in Cant Find A Gaming CMS (CFAGCMS) 1.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the title parameter.

    Source:cr4wl3r
    Published:30 Dec 2008
    5
    Medium

    CVE-2008-5780

    Last Modified: 5 Jan 2017

    Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing passwords via a direct request for blog.mdb.

    Source:Cold Zero
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5779

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:nuclear
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5778

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Source:nuclear
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5777

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:HaCkeR_EgY
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5776

    Last Modified: 6 Jan 2017

    Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to admin.php and the (2) get parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:NoGe
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5775

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:NoGe
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5774

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parameter to (c) detail.asp.

    Source:AlpHaNiX
    Published:30 Dec 2008
    5
    Medium

    CVE-2008-5773

    Last Modified: 23 Apr 2026

    Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb.

    Source:Cyber.Zer0
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5772

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.

    Source:AlpHaNiX
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5771

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

    Source:ahmadbady
    Published:30 Dec 2008
    4.3
    Medium

    CVE-2008-5770

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:ahmadbady
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5768

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:nétRoot
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5767

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.

    Source:AlpHaNiX
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5766

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Aria-Security Team
    Published:30 Dec 2008
    5
    Medium

    CVE-2008-5765

    Last Modified: 23 Apr 2026

    WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for data/usr.txt.

    Source:Osirys
    Published:30 Dec 2008
    9.3
    Critical

    CVE-2008-5764

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

    Source:Osirys
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5763

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter.

    Source:Osirys
    Published:30 Dec 2008
    5
    Medium

    CVE-2008-5762

    Last Modified: 23 Apr 2026

    Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.

    Source:Osirys
    Published:30 Dec 2008