9.3
    Critical

    CVE-2008-5167

    Last Modified: 14 Dec 2016

    PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.

    Source:Ciph3r
    Published:19 Nov 2008
    7.5
    High

    CVE-2008-5166

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.

    Source:InjEctOr5
    Published:19 Nov 2008
    4.3
    Medium

    CVE-2008-5164

    Last Modified: 28 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) viewarticle.php and (b) viewarticle2.php and the (2) PATH_INFO to viewarticle.php.

    Source:CWH Underground
    Published:19 Nov 2008
    7.5
    High

    CVE-2008-5163

    Last Modified: 28 Feb 2014

    Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewarticle.php and (2) viewarticle2.php.

    Source:CWH Underground
    Published:19 Nov 2008
    3.7
    Low

    CVE-2008-5161

    Last Modified: 28 May 2026

    Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.

    Published:19 Nov 2008
    5
    Medium

    CVE-2008-5160

    Last Modified: 23 Nov 2016

    Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with the HTTP GET, DELETE, OPTIONS, and possibly other methods, related to a "204 No Content error."

    Source:shinnai
    Published:18 Nov 2008
    10
    Critical

    CVE-2008-5159

    Last Modified: 28 Jan 2014

    Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption.

    Source:Luigi Auriemma
    Published:18 Nov 2008
    7.5
    High

    CVE-2008-5132

    Last Modified: 13 Nov 2017

    SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

    Source:Ams
    Published:18 Nov 2008
    7.5
    High

    CVE-2008-5131

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).

    Source:InjEctOr5
    Published:18 Nov 2008
    4.3
    Medium

    CVE-2008-5126

    Last Modified: 30 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

    Source:d3v1l
    Published:18 Nov 2008
    6.8
    Medium

    CVE-2008-5125

    Last Modified: 23 Apr 2026

    admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

    Source:t0pP8uZz
    Published:18 Nov 2008
    6.8
    Medium

    CVE-2008-5123

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.

    Source:t0pP8uZz
    Published:18 Nov 2008
    7.2
    High

    CVE-2008-5121

    Last Modified: 23 Apr 2026

    dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.

    Source:mu-b
    Published:18 Nov 2008
    10
    Critical

    CVE-2008-5120

    Last Modified: 12 Mar 2014

    Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.

    Source:Shaun Colley
    Published:18 Nov 2008
    6.8
    Medium

    CVE-2008-5115

    Last Modified: 29 Mar 2014

    Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

    Source:Richard Brain
    Published:18 Nov 2008
    5
    Medium

    CVE-2008-5112

    Last Modified: 30 Mar 2014

    The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.

    Source:Bernardo Damele
    Published:17 Nov 2008
    5
    Medium

    CVE-2008-5105

    Last Modified: 17 Apr 2014

    KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (4) MKD, (5) RMD, (6) RETR, (7) RNFR, (8) RNTO, (9) SIZE, and (10) STOR commands.

    Source:Cod3rZ
    Published:17 Nov 2008
    4
    Medium

    CVE-2008-5102

    Last Modified: 30 Mar 2014

    PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.

    Source:Marc-Andre Lemburg
    Published:11 Nov 2008
    7.5
    High

    CVE-2008-5097

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MyFWB 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:0x90
    Published:14 Nov 2008
    10
    Critical

    CVE-2008-5090

    Last Modified: 5 Jan 2018

    Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.

    Source:GulfTech Security
    Published:14 Nov 2008
    7.5
    High

    CVE-2008-5088

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.

    Source:d3v1l
    Published:14 Nov 2008
    5
    Medium

    CVE-2008-5081

    Last Modified: 23 Apr 2026

    The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.

    Source:Jon Oberheide
    Published:12 Dec 2008
    4.9
    Medium

    CVE-2008-5079

    Last Modified: 6 Jan 2017

    net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.

    Source:Jon Oberheide
    Published:5 Dec 2008
    6.8
    Medium

    CVE-2008-5075

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to (g) browser.php.

    Source:~!Dok_tOR!~
    Published:14 Nov 2008
    7.5
    High

    CVE-2008-5074

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Source:boom3rang
    Published:14 Nov 2008
    9.3
    Critical

    CVE-2008-5073

    Last Modified: 21 Mar 2014

    Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstall method.

    Source:Satan_HackerS
    Published:14 Nov 2008
    4.3
    Medium

    CVE-2008-5072

    Last Modified: 27 Jun 2010

    vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash) via a malformed FLV file.

    Source:Aodrulez
    Published:14 Nov 2008
    9
    Critical

    CVE-2008-5071

    Last Modified: 23 Dec 2016

    Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated users to execute arbitrary PHP code via the proj_id parameter.

    Source:dun
    Published:14 Nov 2008
    7.5
    High

    CVE-2008-5070

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php.

    Source:~!Dok_tOR!~
    Published:14 Nov 2008
    7.5
    High

    CVE-2008-5069

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:14 Nov 2008
    4.3
    Medium

    CVE-2008-5068

    Last Modified: 26 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter to index.php and the (2) searchtext parameter to search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:cize0f
    Published:13 Nov 2008
    4.3
    Medium

    CVE-2008-5067

    Last Modified: 26 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:cize0f
    Published:13 Nov 2008
    10
    Critical

    CVE-2008-5066

    Last Modified: 30 Dec 2016

    PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter.

    Source:DaRkLiFe
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5065

    Last Modified: 23 Apr 2026

    TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.

    Source:x0r
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5064

    Last Modified: 26 Mar 2014

    SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:d3v1l
    Published:13 Nov 2008
    10
    Critical

    CVE-2008-5063

    Last Modified: 14 Dec 2016

    PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbitrary PHP code via a URL in the Tipo parameter.

    Source:Colt7r
    Published:13 Nov 2008
    5
    Medium

    CVE-2008-5062

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read arbitrary files via directory traversal sequences in the thefile parameter.

    Source:ahmadbady
    Published:13 Nov 2008
    4.3
    Medium

    CVE-2008-5061

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in php/cal_default.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Source:ahmadbady
    Published:13 Nov 2008
    10
    Critical

    CVE-2008-5060

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php in include/scripts/; (4) include/misc/mod_2checkout/2checkout_return.inc.php; and (5) include/html/nettools.popup.php, different vectors than CVE-2006-4034 and CVE-2005-1054.

    Source:nigh7f411
    Published:13 Nov 2008
    4.3
    Medium

    CVE-2008-5059

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ModernBill 4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript event in the new_language parameter in a login action.

    Source:nigh7f411
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5058

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in siteadmin/loginsucess.php in Pre Simple CMS allows remote attackers to execute arbitrary SQL commands via the user parameter, as reachable from siteadmin/adminlogin.php. NOTE: some of these details are obtained from third party information.

    Source:Hussin X
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5057

    Last Modified: 29 Mar 2014

    SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL commands via the film parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Kaan KAMIS
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5054

    Last Modified: 2 Jan 2017

    Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_login.php and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information.

    Source:InjEctOr5
    Published:13 Nov 2008
    10
    Critical

    CVE-2008-5053

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:NoGe
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5051

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PostID parameter to index.php.

    Source:boom3rang
    Published:13 Nov 2008
    7.2
    High

    CVE-2008-5049

    Last Modified: 23 Apr 2026

    Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other versions including 3.3.3, allows local users to gain privileges via long inputs to the (1) 0x002224A4, (2) 0x002224C0, and (3) 0x002224CC IOCTL.

    Source:NT Internals
    Published:13 Nov 2008
    7.2
    High

    CVE-2008-5048

    Last Modified: 23 Nov 2017

    Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long inputs to the 0x00222494 IOCTL.

    Source:alex
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5047

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Cyber-Zone
    Published:13 Nov 2008
    7.5
    High

    CVE-2008-5046

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL commands via the manufacturers_id parameter.

    Source:InjEctOr5
    Published:13 Nov 2008
    10
    Critical

    CVE-2008-5045

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to cause a denial of service (crash) via a 200 server response that is exactly 1024 characters long.

    Source:DeltahackingTEAM
    Published:13 Nov 2008