4.3
    Medium

    CVE-2008-5761

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter to the default URI; (2) the foto parameter to photo.php in the 05_Foto module; or (3) the name parameter in an insertrecord action to index.php in the 08_Files module, as demonstrated by injection within a SRC attribute of an IFRAME element.

    Source:gmda
    Published:30 Dec 2008
    4.3
    Medium

    CVE-2008-5759

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web script or HTML via the name parameter in an updaterecord action to index.php in the 08_Files module. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:gmda
    Published:30 Dec 2008
    9.3
    Critical

    CVE-2008-5756

    Last Modified: 23 Apr 2026

    Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service and possibly execute arbitrary code via a long mapping reference in a Color Mapping (.cmap) file.

    Source:Encrypt3d.M!nd
    Published:30 Dec 2008
    9.3
    Critical

    CVE-2008-5755

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP file containing a long URL, possibly a related issue to CVE-2006-2494.

    Source:Guido Landi
    Published:30 Dec 2008
    9.3
    Critical

    CVE-2008-5754

    Last Modified: 28 Apr 2011

    Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753.

    Source:Stack
    Published:30 Dec 2008
    9.3
    Critical

    CVE-2008-5753

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry with a long host name, which appears as a host parameter within the quick-connect bar.

    Source:His0k4
    Published:30 Dec 2008
    4.3
    Medium

    CVE-2008-5752

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information.

    Source:GoLd_M
    Published:30 Dec 2008
    7.5
    High

    CVE-2008-5751

    Last Modified: 18 Dec 2010

    SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.

    Source:Salvatore Fresta
    Published:30 Dec 2008
    6.8
    Medium

    CVE-2008-5750

    Last Modified: 30 Oct 2016

    Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.

    Source:Nine:Situations:Group
    Published:29 Dec 2008
    6.8
    Medium

    CVE-2008-5749

    Last Modified: 30 Oct 2016

    Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission.

    Source:Nine:Situations:Group
    Published:29 Dec 2008
    8.1
    High

    CVE-2008-5748

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

    Source:fuzion
    Published:29 Dec 2008
    4.3
    Medium

    CVE-2008-5745

    Last Modified: 23 Jan 2017

    Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.

    Source:laurent gaffié
    Published:29 Dec 2008
    4
    Medium

    CVE-2008-5742

    Last Modified: 23 Apr 2026

    Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.

    Source:s4avrd0w
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5739

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.

    Source:Ams
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5738

    Last Modified: 23 Apr 2026

    Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2 cookie to 1. NOTE: some of these details are obtained from third party information.

    Source:Osirys
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5737

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:StAkeR
    Published:26 Dec 2008
    7.2
    High

    CVE-2008-5736

    Last Modified: 30 Jan 2017

    Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown attack vectors related to function pointers that are "not properly initialized" for (1) netgraph sockets and (2) bluetooth sockets.

    Source:zx2c4
    Published:26 Dec 2008
    9.3
    Critical

    CVE-2008-5735

    Last Modified: 6 Jan 2017

    Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code via a large PlaylistSkin value in a skin file.

    Source:r0ut3r
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5733

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5732

    Last Modified: 6 Jan 2017

    Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.

    Source:Piker
    Published:26 Dec 2008
    4.9
    Medium

    CVE-2008-5731

    Last Modified: 23 Apr 2026

    The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows local users to cause a denial of service (system crash) and possibly gain privileges via a certain METHOD_BUFFERED IOCTL request that overwrites portions of memory, related to a "Driver Collapse." NOTE: some of these details are obtained from third party information.

    Source:Evilcry
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5730

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vectors involving (1) a %0a sequence in a cookie and (2) the add.php file.

    Source:s4avrd0w
    Published:26 Dec 2008
    4.3
    Medium

    CVE-2008-5729

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) form and (2) control parameters to FCKeditor/neditor.php, and the (3) path parameter to admin/siteinfo/iframe.inc.php.

    Source:s4avrd0w
    Published:26 Dec 2008
    5.1
    Medium

    CVE-2008-5728

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the system parameter in modules/netshop/post.php; and the INCLUDE_FOLDER parameter in (2) auth.inc.php, (3) banner.inc.php, (4) blog.inc.php, and (5) forum.inc.php in modules/.

    Source:s4avrd0w
    Published:26 Dec 2008
    6.8
    Medium

    CVE-2008-5727

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the query string.

    Source:s4avrd0w
    Published:26 Dec 2008
    7.5
    High

    CVE-2008-5726

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Samir-M
    Published:26 Dec 2008
    7.2
    High

    CVE-2008-5725

    Last Modified: 23 Apr 2026

    The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local users to gain privileges via certain IRP parameters in an IOCTL request to \Device\Powerstrip1 that overwrites portions of memory.

    Source:NT Internals
    Published:26 Dec 2008
    7.2
    High

    CVE-2008-5724

    Last Modified: 23 Apr 2026

    The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges via a crafted IRP in a certain METHOD_NEITHER IOCTL request to \Device\Epfw that overwrites portions of memory.

    Source:NT Internals
    Published:26 Dec 2008
    10
    Critical

    CVE-2008-5722

    Last Modified: 23 Apr 2026

    Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file.

    Source:Encrypt3d.M!nd
    Published:26 Dec 2008
    5
    Medium

    CVE-2008-5715

    Last Modified: 6 Jan 2017

    Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported that earlier versions are also affected, and that the impact is CPU consumption and application hang in unspecified circumstances perhaps involving other platforms.

    Source:Jeremy Brown
    Published:24 Dec 2008
    4.9
    Medium

    CVE-2008-5713

    Last Modified: 6 Sept 2016

    The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocations of the Netperf benchmark application in UDP_STREAM mode.

    Source:Herbert Xu
    Published:28 Mar 2008
    5
    Medium

    CVE-2008-5712

    Last Modified: 23 Apr 2026

    The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514.

    Source:Jeremy Brown
    Published:24 Dec 2008
    9.3
    Critical

    CVE-2008-5711

    Last Modified: 10 Mar 2011

    Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value.

    Source:Metasploit
    Published:24 Dec 2008
    7.5
    High

    CVE-2008-5708

    Last Modified: 2 Jan 2017

    redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.

    Source:StAkeR
    Published:24 Dec 2008
    7.5
    High

    CVE-2008-5707

    Last Modified: 25 Mar 2014

    SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter.

    Source:tRoot
    Published:23 Dec 2008
    6.9
    Medium

    CVE-2008-5706

    Last Modified: 23 Apr 2026

    The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file.

    Source:v4lkyrius
    Published:22 Dec 2008
    9.3
    Critical

    CVE-2008-5705

    Last Modified: 23 Apr 2026

    The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an argument.

    Source:v4lkyrius
    Published:22 Dec 2008
    4.3
    Medium

    CVE-2008-5698

    Last Modified: 10 Oct 2017

    HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party information.

    Source:Jeremy Brown
    Published:22 Dec 2008
    4.3
    Medium

    CVE-2008-5697

    Last Modified: 7 Oct 2017

    The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument.

    Source:irk4z
    Published:22 Dec 2008
    8.5
    High

    CVE-2008-5695

    Last Modified: 23 Apr 2026

    wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.

    Source:Alexander Concha
    Published:19 Dec 2008
    5
    Medium

    CVE-2008-5692

    Last Modified: 21 Jan 2014

    Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.

    Source:Luigi Auriemma
    Published:19 Dec 2008
    9.3
    Critical

    CVE-2008-5691

    Last Modified: 27 Apr 2011

    Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute arbitrary code via a long argument to the SetID method.

    Source:e.wiZz!
    Published:19 Dec 2008
    7.2
    High

    CVE-2008-5689

    Last Modified: 10 Jan 2011

    tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.

    Source:peri.carding
    Published:19 Dec 2008
    9.3
    Critical

    CVE-2008-5680

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-assisted remote attackers to execute arbitrary code via a long host name in a file: URL. NOTE: this might overlap CVE-2008-5178.

    Source:Guido Landi
    Published:19 Dec 2008
    4
    Medium

    CVE-2008-5678

    Last Modified: 23 Dec 2016

    Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files.

    Source:ZeN
    Published:18 Dec 2008
    7.1
    High

    CVE-2008-5677

    Last Modified: 30 Dec 2016

    Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information.

    Source:CWH Underground
    Published:18 Dec 2008
    9.4
    Critical

    CVE-2008-5674

    Last Modified: 28 Jan 2014

    Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum parameter to the pocketpc component and (2) an invalid id parameter to the show_gallery_pic component.

    Source:Luigi Auriemma
    Published:18 Dec 2008
    5
    Medium

    CVE-2008-5667

    Last Modified: 23 Apr 2026

    The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and application crash) via a malformed RAR archive.

    Source:LiquidWorm
    Published:18 Dec 2008
    3.5
    Low

    CVE-2008-5666

    Last Modified: 23 Dec 2016

    WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.

    Source:Julien Bedard
    Published:18 Dec 2008
    7.5
    High

    CVE-2008-5665

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.

    Source:EcHoLL
    Published:18 Dec 2008