6.8
    Medium

    CVE-2008-5267

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter.

    Source:CWH Underground
    Published:28 Nov 2008
    4.3
    Medium

    CVE-2008-5266

    Last Modified: 26 Feb 2014

    Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.

    Source:Eduardo Neves
    Published:28 Nov 2008
    6.8
    Medium

    CVE-2008-5265

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modulo parameter.

    Source:CWH Underground
    Published:28 Nov 2008
    4.3
    Medium

    CVE-2008-5264

    Last Modified: 25 Feb 2014

    Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the p parameter in a root action.

    Source:Unohope
    Published:28 Nov 2008
    9.3
    Critical

    CVE-2008-5232

    Last Modified: 16 Mar 2014

    Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Jeremy Brown
    Published:26 Nov 2008
    6.9
    Medium

    CVE-2008-5229

    Last Modified: 30 Mar 2014

    Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.

    Source:Marius Wachtler
    Published:25 Nov 2008
    7.5
    High

    CVE-2008-5226

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a different vector than CVE-2007-5177.

    Source:Houssamix
    Published:25 Nov 2008
    4.3
    Medium

    CVE-2008-5225

    Last Modified: 24 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.

    Source:Doz
    Published:25 Nov 2008
    7.5
    High

    CVE-2008-5223

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:QTRinux
    Published:25 Nov 2008
    7.5
    High

    CVE-2008-5222

    Last Modified: 24 Feb 2014

    SQL injection vulnerability in login.asp in Dvbbs 8.2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:hackerbinhphuoc
    Published:25 Nov 2008
    7.5
    High

    CVE-2008-5221

    Last Modified: 6 Jan 2017

    The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters.

    Source:G4N0K
    Published:25 Nov 2008
    10
    Critical

    CVE-2008-5220

    Last Modified: 25 Sept 2016

    Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in admin/tmp/.

    Source:Osirys
    Published:25 Nov 2008
    7.5
    High

    CVE-2008-5219

    Last Modified: 23 Apr 2026

    The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

    Source:G4N0K
    Published:25 Nov 2008
    5
    Medium

    CVE-2008-5218

    Last Modified: 23 Apr 2026

    ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.

    Source:cOndemned
    Published:25 Nov 2008
    5.1
    Medium

    CVE-2008-5217

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in txtCMS 0.3, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.

    Source:cOndemned
    Published:24 Nov 2008
    7.5
    High

    CVE-2008-5216

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:t0pP8uZz
    Published:24 Nov 2008
    7.5
    High

    CVE-2008-5215

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary SQL commands via the link parameter.

    Source:ZoRLu
    Published:24 Nov 2008
    4.3
    Medium

    CVE-2008-5214

    Last Modified: 28 Nov 2016

    Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.

    Source:ZoRLu
    Published:24 Nov 2008
    7.5
    High

    CVE-2008-5213

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.

    Source:t0pP8uZz
    Published:24 Nov 2008
    7.5
    High

    CVE-2008-5212

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Source:t0pP8uZz
    Published:24 Nov 2008
    2.6
    Low

    CVE-2008-5211

    Last Modified: 19 Feb 2014

    Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attackers to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.

    Source:Christian Holler
    Published:24 Nov 2008
    9.3
    Critical

    CVE-2008-5210

    Last Modified: 24 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter to (1) script/init/createallimagecache.php, (2) allincludefortick.php and (3) test.php in script/tick/, and (4) modules/dungeon/tick/allincludefortick.php, different vectors than CVE-2008-1776.

    Source:CraCkEr
    Published:24 Nov 2008
    5
    Medium

    CVE-2008-5209

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:n3v3rh00d
    Published:24 Nov 2008
    7.5
    High

    CVE-2008-5208

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

    Source:+toxa+
    Published:24 Nov 2008
    6.8
    Medium

    CVE-2008-5204

    Last Modified: 9 Dec 2016

    Multiple directory traversal vulnerabilities in PowerAward 1.1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter to (1) agb.php, (2) angemeldet.php, (3) anmelden.php, (4) charts.php, (5) external_vote.php, (6) guestbook.php, (7) impressum.php, (8) index.php, (9) rss-reader.php, (10) statistic.php, (11) teilnehmer.php, (12) topsites.php, (13) votecode.php, (14) voting.php, and (15) winner.php.

    Source:CraCkEr
    Published:21 Nov 2008
    4.3
    Medium

    CVE-2008-5203

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in external_vote.php in PowerAward 1.1.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the l_vote_done parameter.

    Source:CraCkEr
    Published:21 Nov 2008
    4.3
    Medium

    CVE-2008-5202

    Last Modified: 14 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in OTManager CMS 24a allows remote attackers to inject arbitrary web script or HTML via the conteudo parameter.

    Source:CWH Underground
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5201

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conteudo parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:CWH Underground
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5200

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:His0k4
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5199

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include.php in PHPOutsourcing IdeaBox (aka IdeBox) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the gorumDir parameter.

    Source:Kacper
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5198

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL commands via the pow parameter.

    Source:anonymous
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5197

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the lid parameter in a detail_adverts action.

    Source:boom3rang
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5196

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:boom3rang
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5195

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.

    Source:shinmai
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5194

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in checkavail.php in SoftVisions Software Online Booking Manager (obm) 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:21 Nov 2008
    4.3
    Medium

    CVE-2008-5193

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: this might overlap CVE-2007-4024.

    Source:Bl@ckbe@rD
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5192

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might overlap CVE-2008-2334, CVE-2008-1939, CVE-2007-2641, or CVE-2007-0920.

    Source:Bl@ckbe@rD
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5191

    Last Modified: 14 Dec 2016

    Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) poll_id parameter to poll.php and the (2) sp_id parameter to staticpages.php.

    Source:jsass
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5190

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in eSHOP100 allows remote attackers to execute arbitrary SQL commands via the SUB parameter.

    Source:JuDge
    Published:21 Nov 2008
    5
    Medium

    CVE-2008-5185

    Last Modified: 30 Mar 2014

    The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequence containing an opening delimiter without a closing delimiter, as demonstrated using "<".

    Source:Christian Hoffmann
    Published:21 Nov 2008
    7.5
    High

    CVE-2008-5183

    Last Modified: 23 Apr 2026

    cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.

    Source:Adrian _pagvac_ Pastor
    Published:15 Nov 2008
    5.3
    Medium

    CVE-2008-5180

    Last Modified: 23 Apr 2026

    Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.

    Source:Praveen Darshanam
    Published:20 Nov 2008
    9.3
    Critical

    CVE-2008-5178

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.

    Source:Guido Landi
    Published:20 Nov 2008
    10
    Critical

    CVE-2008-5177

    Last Modified: 29 Mar 2014

    Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly execute arbitrary code on a Windows platform, related to ytwindtb.dll; via a long username field during authentication.

    Source:Abdul-Aziz Hariri
    Published:20 Nov 2008
    9.3
    Critical

    CVE-2008-5175

    Last Modified: 1 Mar 2014

    Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

    Source:Tan Chew Keong
    Published:19 Nov 2008
    7.5
    High

    CVE-2008-5174

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.

    Source:InjEctOr5
    Published:19 Nov 2008
    9.3
    Critical

    CVE-2008-5171

    Last Modified: 14 Dec 2016

    Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) DB, (2) lang, and (3) skin parameters.

    Source:CraCkEr
    Published:19 Nov 2008
    7.5
    High

    CVE-2008-5170

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

    Source:InjEctOr5
    Published:19 Nov 2008
    7.5
    High

    CVE-2008-5169

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.

    Source:InjEctOr5
    Published:19 Nov 2008
    7.5
    High

    CVE-2008-5168

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter.

    Source:InjEctOr5
    Published:19 Nov 2008