9.3
    Critical

    CVE-2008-5406

    Last Modified: 11 Nov 2016

    Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."

    Source:laurent gaffié
    Published:9 Dec 2008
    9.3
    Critical

    CVE-2008-5405

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an RDP file containing a long string.

    Source:Metasploit
    Published:9 Dec 2008
    7.2
    High

    CVE-2008-5394

    Last Modified: 23 Apr 2026

    /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.

    Source:Paul Szabo
    Published:9 Dec 2008
    9.3
    Critical

    CVE-2008-5383

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .ewb file.

    Source:Zigma
    Published:9 Dec 2008
    6.9
    Medium

    CVE-2008-5377

    Last Modified: 5 Jan 2017

    pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.

    Source:Jon Oberheide
    Published:8 Dec 2008
    7.5
    High

    CVE-2008-5365

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.

    Source:R3d-D3V!L
    Published:8 Dec 2008
    10
    Critical

    CVE-2008-5353

    Last Modified: 6 Mar 2011

    The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

    Source:Metasploit
    Published:4 Dec 2008
    4.3
    Medium

    CVE-2008-5338

    Last Modified: 3 Jan 2017

    Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Source:ZoRLu
    Published:5 Dec 2008
    7.5
    High

    CVE-2008-5337

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ZoRLu
    Published:5 Dec 2008
    7.5
    High

    CVE-2008-5336

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

    Source:Glafkos Charalambous
    Published:5 Dec 2008
    6.8
    Medium

    CVE-2008-5335

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.

    Source:irk4z
    Published:5 Dec 2008
    10
    Critical

    CVE-2008-5334

    Last Modified: 6 Jan 2017

    PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:Osirys
    Published:5 Dec 2008
    7.5
    High

    CVE-2008-5333

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Osirys
    Published:5 Dec 2008
    10
    Critical

    CVE-2008-5332

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php, (b) cancel.php, (c) context.php, (d) deadlinks.php, (e) delete.php, and others; and the (2) GLOBALS[pie][library_path] parameter to files in lib/share/ including (f) diff.php, (g) file.php, (h) locale.php, (i) mapfile.php, (j) page.php, and others.

    Source:NoGe
    Published:5 Dec 2008
    4.3
    Medium

    CVE-2008-5330

    Last Modified: 1 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

    Source:IBM
    Published:5 Dec 2008
    4.3
    Medium

    CVE-2008-5323

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Source:StAkeR
    Published:3 Dec 2008
    7.8
    High

    CVE-2008-5322

    Last Modified: 23 Apr 2026

    Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.

    Source:StAkeR
    Published:3 Dec 2008
    7.5
    High

    CVE-2008-5321

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.

    Source:EcHoLL
    Published:3 Dec 2008
    6.5
    Medium

    CVE-2008-5320

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.

    Source:girex
    Published:3 Dec 2008
    4.3
    Medium

    CVE-2008-5314

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.

    Source:ilja van sprundel
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5311

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:snakespc
    Published:2 Dec 2008
    7.5
    High

    CVE-2008-5310

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:snakespc
    Published:2 Dec 2008
    7.5
    High

    CVE-2008-5309

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.

    Source:Hussin X
    Published:2 Dec 2008
    7.5
    High

    CVE-2008-5308

    Last Modified: 26 Dec 2010

    The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.

    Source:cOndemned
    Published:2 Dec 2008
    7.5
    High

    CVE-2008-5307

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:2 Dec 2008
    7.5
    High

    CVE-2008-5306

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:2 Dec 2008
    10
    Critical

    CVE-2008-5305

    Last Modified: 2 Apr 2014

    Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

    Source:Troy Bollinge
    Published:10 Dec 2008
    4.3
    Medium

    CVE-2008-5304

    Last Modified: 2 Apr 2014

    Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.

    Source:Marc Schoenefeld
    Published:10 Dec 2008
    7.6
    High

    CVE-2008-5297

    Last Modified: 23 Apr 2026

    Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.

    Source:XenoMuta
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5295

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.

    Source:XaDoS
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5294

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

    Source:Hussin X
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5293

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

    Source:Hussin X
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5292

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Source:Cyber-Zone
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5291

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.

    Source:Alfons Luja
    Published:1 Dec 2008
    4.3
    Medium

    CVE-2008-5290

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:ZoRLu
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5289

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JosS
    Published:1 Dec 2008
    6.8
    Medium

    CVE-2008-5288

    Last Modified: 3 Jan 2017

    PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config_path parameter.

    Source:ZoRLu
    Published:1 Dec 2008
    7.5
    High

    CVE-2008-5287

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:cOndemned
    Published:1 Dec 2008
    10
    Critical

    CVE-2008-5284

    Last Modified: 11 Jul 2017

    The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier, allows remote attackers to cause a denial of service (crash) via an HTTP Content-Length header with a negative value, which triggers a single byte overwrite of memory using a NULL terminator. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:29 Nov 2008
    6.4
    Medium

    CVE-2008-5283

    Last Modified: 28 Jan 2014

    Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most recent version as of 20081128 is 1.2, and the File Upload Manager does not have a "delall" action.

    Source:Mr-m07
    Published:29 Nov 2008
    10
    Critical

    CVE-2008-5282

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.

    Source:r0ut3r
    Published:29 Nov 2008
    10
    Critical

    CVE-2008-5281

    Last Modified: 9 Nov 2016

    Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command.

    Source:j0rgan
    Published:29 Nov 2008
    5
    Medium

    CVE-2008-5280

    Last Modified: 5 Feb 2014

    The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted requests without required parameters.

    Source:Luigi Auriemma
    Published:29 Nov 2008
    5
    Medium

    CVE-2008-5274

    Last Modified: 23 Apr 2026

    Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Bl@ckbe@rD
    Published:28 Nov 2008
    7.5
    High

    CVE-2008-5273

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute arbitrary SQL commands via the newsID parameter.

    Source:Bl@ckbe@rD
    Published:28 Nov 2008
    4
    Medium

    CVE-2008-5272

    Last Modified: 7 Dec 2016

    Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the template parameter to (1) starnet/editors/fckeditor/studenteditor.php; (2) starnet/modules/sn_news/edit_content.php, reached through starnet/index.php; and (3) starnet/modules/sn_newsletter/edit_content.php, reached through starnet/index.php.

    Source:CWH Underground
    Published:28 Nov 2008
    4.3
    Medium

    CVE-2008-5271

    Last Modified: 7 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Source:CWH Underground
    Published:28 Nov 2008
    7.5
    High

    CVE-2008-5270

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.

    Source:RMx
    Published:28 Nov 2008
    7.5
    High

    CVE-2008-5269

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter.

    Source:anonymous
    Published:28 Nov 2008
    7.5
    High

    CVE-2008-5268

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL commands via the Topic_Id parameter.

    Source:JosS
    Published:28 Nov 2008