4
    Medium

    CVE-2008-5044

    Last Modified: 29 Mar 2014

    Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.

    Source:killprog.org
    Published:12 Nov 2008
    7.5
    High

    CVE-2008-5042

    Last Modified: 23 Apr 2026

    Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php.

    Source:Stack
    Published:12 Nov 2008
    7.5
    High

    CVE-2008-5040

    Last Modified: 23 Apr 2026

    Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.

    Source:Stack
    Published:12 Nov 2008
    4.3
    Medium

    CVE-2008-5039

    Last Modified: 26 Mar 2014

    Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php.

    Source:Ehsan_Hp200
    Published:12 Nov 2008
    7.5
    High

    CVE-2008-5037

    Last Modified: 26 Mar 2014

    SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:G4N0K
    Published:12 Nov 2008
    9.3
    Critical

    CVE-2008-5036

    Last Modified: 15 Nov 2016

    Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.

    Source:Metasploit
    Published:10 Nov 2008
    9.3
    Critical

    CVE-2008-5032

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.

    Source:Dr_IDE
    Published:10 Nov 2008
    10
    Critical

    CVE-2008-5010

    Last Modified: 14 Jul 2017

    in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.

    Source:RoMaNSoFt
    Published:10 Nov 2008
    7.5
    High

    CVE-2008-5004

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbitrary SQL commands via a crafted cookie.

    Source:JosS
    Published:10 Nov 2008
    7.5
    High

    CVE-2008-5003

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:BazOka-HaCkEr
    Published:10 Nov 2008
    9.3
    Critical

    CVE-2008-5002

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:10 Nov 2008
    6.8
    Medium

    CVE-2008-5000

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via uppercase characters in the news_id parameter.

    Source:StAkeR
    Published:10 Nov 2008
    7.8
    High

    CVE-2008-4999

    Last Modified: 31 Jan 2014

    Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: this issue could not be reproduced by a third party, who tested it on 0604DAD. In addition, the original researcher was not able to reliably reproduce the issue.

    Source:sipherr
    Published:7 Nov 2008
    9
    Critical

    CVE-2008-4932

    Last Modified: 23 Apr 2026

    webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.

    Source:Shennan Wang
    Published:5 Nov 2008
    4.3
    Medium

    CVE-2008-4931

    Last Modified: 28 Mar 2014

    Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the action parameter to index.php.

    Source:Brad Antoniewicz
    Published:5 Nov 2008
    9
    Critical

    CVE-2008-4926

    Last Modified: 24 Jul 2010

    Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Source:DeltahackingTEAM
    Published:4 Nov 2008
    9
    Critical

    CVE-2008-4925

    Last Modified: 2 Jan 2017

    Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Source:DeltahackingTEAM
    Published:4 Nov 2008
    9
    Critical

    CVE-2008-4924

    Last Modified: 2 Jan 2017

    Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Source:DeltahackingTEAM
    Published:4 Nov 2008
    9
    Critical

    CVE-2008-4923

    Last Modified: 2 Jan 2017

    Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Source:DeltahackingTEAM
    Published:4 Nov 2008
    9.3
    Critical

    CVE-2008-4922

    Last Modified: 10 Mar 2011

    Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.

    Source:Metasploit
    Published:4 Nov 2008
    8.8
    High

    CVE-2008-4919

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method.

    Source:Marco Torti
    Published:4 Nov 2008
    4.3
    Medium

    CVE-2008-4918

    Last Modified: 27 Mar 2014

    Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."

    Source:pagvac
    Published:4 Nov 2008
    5
    Medium

    CVE-2008-4913

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

    Source:cOndemned
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4912

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

    Source:S@BUN
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4911

    Last Modified: 14 Feb 2014

    PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL in the data parameter.

    Source:THuGM4N
    Published:4 Nov 2008
    10
    Critical

    CVE-2008-4910

    Last Modified: 26 Mar 2014

    The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.

    Source:Varun Srivastava
    Published:3 Nov 2008
    4.3
    Medium

    CVE-2008-4907

    Last Modified: 27 Mar 2014

    The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."

    Source:anonymous
    Published:30 Oct 2008
    7.5
    High

    CVE-2008-4906

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4902

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Source:Stack
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4901

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Hakxer
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4900

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:4 Nov 2008
    6.8
    Medium

    CVE-2008-4897

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the art parameter.

    Source:ZoRLu
    Published:4 Nov 2008
    4.3
    Medium

    CVE-2008-4896

    Last Modified: 2 Jan 2017

    Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the art parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4895

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:4 Nov 2008
    5.1
    Medium

    CVE-2008-4894

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the template_path parameter. NOTE: it was later reported that this issue also affects 5.0.12c.

    Source:GoLd_M
    Published:4 Nov 2008
    2.6
    Low

    CVE-2008-4893

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the template_path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:GoLd_M
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-4890

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:TR-ShaRk
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4889

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action.

    Source:anonymous
    Published:3 Nov 2008
    4.3
    Medium

    CVE-2008-4888

    Last Modified: 2 Jan 2017

    Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:StAkeR
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4887

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php). NOTE: some of these details are obtained from third party information.

    Source:StAkeR
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4886

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:Hussin X
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4885

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4884

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4883

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4882

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4881

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4880

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.

    Source:d3v1l
    Published:3 Nov 2008
    7.5
    High

    CVE-2008-4879

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.

    Source:JosS
    Published:3 Nov 2008
    8.5
    High

    CVE-2008-4878

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file.

    Source:t0pP8uZz
    Published:31 Oct 2008
    6.8
    Medium

    CVE-2008-4877

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these details are obtained from third party information.

    Source:t0pP8uZz
    Published:31 Oct 2008