4.3
    Medium

    CVE-2008-5591

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter and possibly other "login fields." NOTE: some of these details are obtained from third party information.

    Source:AlpHaNiX
    Published:16 Dec 2008
    7.5
    High

    CVE-2008-5590

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remote attackers to execute arbitrary SQL commands via the forum_topic_id parameter.

    Source:b3hz4d
    Published:16 Dec 2008
    7.5
    High

    CVE-2008-5589

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL commands via the (1) txtusername parameter (aka username field) or the (2) txtpassword parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Source:AlpHaNiX
    Published:16 Dec 2008
    7.5
    High

    CVE-2008-5588

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL commands via the siteID parameter.

    Source:AlpHaNiX
    Published:16 Dec 2008
    4.3
    Medium

    CVE-2008-5587

    Last Modified: 6 Jan 2017

    Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the _language parameter to index.php.

    Source:dun
    Published:16 Dec 2008
    6.8
    Medium

    CVE-2008-5586

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:CWH Underground
    Published:16 Dec 2008
    7.5
    High

    CVE-2008-5585

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.

    Source:NoGe
    Published:16 Dec 2008
    4.3
    Medium

    CVE-2008-5584

    Last Modified: 28 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.

    Source:L4teral
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5582

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Source:r3dm0v3
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5581

    Last Modified: 2 Jan 2017

    PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.

    Source:muuratsalo
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5580

    Last Modified: 2 Jan 2017

    mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argument.

    Source:muuratsalo
    Published:15 Dec 2008
    5
    Medium

    CVE-2008-5579

    Last Modified: 2 Jan 2017

    Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read arbitrary files via a full pathname in the sFileName parameter.

    Source:muuratsalo
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5578

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.

    Source:Inphex
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5577

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.

    Source:Inphex
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5576

    Last Modified: 23 Apr 2026

    admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.

    Source:Inphex
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5574

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.

    Source:Hussin X
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5573

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.

    Source:AlpHaNiX
    Published:15 Dec 2008
    5
    Medium

    CVE-2008-5572

    Last Modified: 23 Apr 2026

    Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.

    Source:Ghost Hacker
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5571

    Last Modified: 4 Jan 2017

    SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:15 Dec 2008
    6.8
    Medium

    CVE-2008-5570

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:ahmadbady
    Published:15 Dec 2008
    4.3
    Medium

    CVE-2008-5569

    Last Modified: 2 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/.

    Source:th3.r00k.ieatpork
    Published:15 Dec 2008
    6.8
    Medium

    CVE-2008-5568

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the admin_id, newpass_1, and newpass_2 parameters.

    Source:G4N0K
    Published:15 Dec 2008
    6.8
    Medium

    CVE-2008-5567

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.

    Source:G4N0K
    Published:15 Dec 2008
    4.3
    Medium

    CVE-2008-5566

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:ahmadbady
    Published:15 Dec 2008
    6.8
    Medium

    CVE-2008-5565

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.

    Source:G4N0K
    Published:15 Dec 2008
    5
    Medium

    CVE-2008-5562

    Last Modified: 4 Jan 2017

    ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for xportal.mdb.

    Source:ZoRLu
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5561

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) fiche_product.php and (2) presentation.php.

    Source:SuB-ZeRo
    Published:15 Dec 2008
    5
    Medium

    CVE-2008-5560

    Last Modified: 23 Apr 2026

    PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb.

    Source:AlpHaNiX
    Published:15 Dec 2008
    7.5
    High

    CVE-2008-5559

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:AlpHaNiX
    Published:15 Dec 2008
    4.3
    Medium

    CVE-2008-5551

    Last Modified: 2 Apr 2014

    The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."

    Source:Rafel Ivgi
    Published:12 Dec 2008
    9.4
    Critical

    CVE-2008-5518

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.

    Source:DSecRG
    Published:17 Apr 2009
    7.5
    High

    CVE-2008-5517

    Last Modified: 23 Apr 2026

    The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.

    Source:S2 Crew
    Published:13 Jan 2009
    9.3
    Critical

    CVE-2008-5499

    Last Modified: 20 Apr 2012

    Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file.

    Source:Metasploit
    Published:17 Dec 2008
    5
    Medium

    CVE-2008-5498

    Last Modified: 23 Jan 2017

    Array index error in the imageRotate function in PHP 5.2.8 and earlier allows context-dependent attackers to read the contents of arbitrary memory locations via a crafted value of the third argument (aka the bgd_color or clrBack argument) for an indexed image.

    Source:Hamid Ebadi
    Published:24 Dec 2008
    7.5
    High

    CVE-2008-5497

    Last Modified: 21 Dec 2016

    BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true.

    Source:Stack
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5496

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Hussin X
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5494

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:boom3rang
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5493

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:12 Dec 2008
    9.3
    Critical

    CVE-2008-5492

    Last Modified: 30 Mar 2014

    Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. NOTE: some of these details are obtained from third party information.

    Source:r0ut3r
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5491

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.

    Source:StAkeR
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5490

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:snakespc
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5489

    Last Modified: 27 Mar 2013

    SQL injection vulnerability in channel_detail.php in ClipShare Pro 4, and 2006 through 2007, allows remote attackers to execute arbitrary SQL commands via the chid parameter.

    Source:Esac
    Published:12 Dec 2008
    4.3
    Medium

    CVE-2008-5487

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:ZoRLu
    Published:12 Dec 2008
    7.5
    High

    CVE-2008-5486

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ZoRLu
    Published:12 Dec 2008
    10
    Critical

    CVE-2008-5457

    Last Modified: 10 Mar 2011

    Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Source:Metasploit
    Published:14 Jan 2009
    10
    Critical

    CVE-2008-5444

    Last Modified: 7 Mar 2011

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and CVE-2008-5449.

    Source:Metasploit
    Published:14 Jan 2009
    5
    Medium

    CVE-2008-5431

    Last Modified: 23 Apr 2026

    Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3) a certain PORT command.

    Source:Greg Linares
    Published:11 Dec 2008
    5.1
    Medium

    CVE-2008-5418

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in the PunPortal module before 2.0 for PunBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter.

    Source:StAkeR
    Published:10 Dec 2008
    9
    Critical

    CVE-2008-5416

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and Windows Internal Database (WYukon) SP2 allows remote authenticated users to cause a denial of service (access violation exception) or execute arbitrary code by calling the sp_replwritetovarbin extended stored procedure with a set of invalid parameters that trigger memory overwrite, aka "SQL Server sp_replwritetovarbin Limited Memory Overwrite Vulnerability."

    Source:Guido Landi
    Published:10 Dec 2008
    9.3
    Critical

    CVE-2008-5409

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, possibly related to included compressed streams that were processed with the ASCIIHexDecode filter. NOTE: some of these details are obtained from third party information.

    Source:ProTeuS
    Published:9 Dec 2008