4.3
    Medium

    CVE-2008-4876

    Last Modified: 24 Jan 2017

    Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.

    Source:ikki
    Published:31 Oct 2008
    6.8
    Medium

    CVE-2008-4875

    Last Modified: 24 Jan 2017

    Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files such as (1) save.dat and (2) apply.log, which can contain other credentials such as the Skype username and password.

    Source:ikki
    Published:31 Oct 2008
    5
    Medium

    CVE-2008-4874

    Last Modified: 24 Jan 2017

    The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.

    Source:ikki
    Published:31 Oct 2008
    10
    Critical

    CVE-2008-4873

    Last Modified: 30 Dec 2016

    board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.

    Source:GoLd_M
    Published:31 Oct 2008
    7.5
    High

    CVE-2008-4864

    Last Modified: 23 Apr 2026

    Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow, a different vulnerability than CVE-2007-4965 and CVE-2008-1679.

    Source:Chris Evans
    Published:19 Oct 2008
    9.3
    Critical

    CVE-2008-4844

    Last Modified: 25 May 2017

    Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.

    Source:muts
    Published:11 Dec 2008
    9.3
    Critical

    CVE-2008-4841

    Last Modified: 23 Apr 2026

    The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.

    Source:securfrog
    Published:10 Dec 2008
    9.3
    Critical

    CVE-2008-4830

    Last Modified: 10 Mar 2011

    Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or execute arbitrary files via the OpenDocument method.

    Source:Metasploit
    Published:16 Apr 2009
    10
    Critical

    CVE-2008-4828

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.

    Source:Metasploit
    Published:5 May 2009
    4.3
    Medium

    CVE-2008-4803

    Last Modified: 31 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:31 Oct 2008
    5
    Medium

    CVE-2008-4800

    Last Modified: 27 Mar 2014

    The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the GetEntryPointForThread method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.

    Source:suN8Hclf
    Published:30 Oct 2008
    4.3
    Medium

    CVE-2008-4795

    Last Modified: 27 Mar 2014

    The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.

    Source:Stefano Di Paola
    Published:30 Oct 2008
    5.8
    Medium

    CVE-2008-4787

    Last Modified: 26 Mar 2014

    Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a URL with a hostname containing many   (Non-Blocking Space character) sequences, which are rendered as whitespace, aka MSRC ticket MSRC7899, a related issue to CVE-2003-1025.

    Source:Amit Klein
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4786

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:StAkeR
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4785

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:boom3rang
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4784

    Last Modified: 23 Apr 2026

    aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.

    Source:JosS
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4783

    Last Modified: 23 Apr 2026

    tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."

    Source:x0r
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4782

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

    Source:ExSploiters
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4781

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langage parameter.

    Source:x0r
    Published:29 Oct 2008
    6.8
    Medium

    CVE-2008-4780

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the padmin parameter.

    Source:Vrs-hCk
    Published:29 Oct 2008
    10
    Critical

    CVE-2008-4779

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary code via a long filename in a .zip file.

    Source:fl0 fl0w
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4778

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.

    Source:JosS
    Published:29 Oct 2008
    7.5
    High

    CVE-2008-4777

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showTests task.

    Source:The-0utl4w
    Published:29 Oct 2008
    2.6
    Low

    CVE-2008-4775

    Last Modified: 26 Mar 2014

    Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.

    Source:Hadi Kiamarsi
    Published:27 Oct 2008
    4.3
    Medium

    CVE-2008-4774

    Last Modified: 30 Dec 2016

    Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web script or HTML via the cx parameter.

    Source:d3b4g
    Published:28 Oct 2008
    5
    Medium

    CVE-2008-4773

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via a .. (dot dot) in the theme parameter.

    Source:d3b4g
    Published:28 Oct 2008
    7.5
    High

    CVE-2008-4772

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via the obj parameter.

    Source:d3b4g
    Published:28 Oct 2008
    9.3
    Critical

    CVE-2008-4771

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers to execute arbitrary code via a long Url property. NOTE: some of these details are obtained from third party information.

    Source:rgod
    Published:28 Oct 2008
    9.3
    Critical

    CVE-2008-4769

    Last Modified: 4 May 2017

    Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information.

    Source:Gerendi Sandor Attila
    Published:28 Oct 2008
    7.5
    High

    CVE-2008-4768

    Last Modified: 14 Feb 2014

    SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. NOTE: the goodies.php vector is already covered by CVE-2007-4808. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:28 Oct 2008
    9
    Critical

    CVE-2008-4767

    Last Modified: 17 Feb 2014

    Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3) .txt extensions, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: it is unclear how allowing the upload of .html or .txt files supports arbitrary code execution; this might be legitimate functionality.

    Source:ZoRLu
    Published:28 Oct 2008
    7.5
    High

    CVE-2008-4765

    Last Modified: 13 Feb 2014

    SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbitrary SQL commands via the pollID parameter in a results operation. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

    Source:S@BUN
    Published:28 Oct 2008
    5
    Medium

    CVE-2008-4764

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.

    Source:Houssamix
    Published:28 Oct 2008
    9
    Critical

    CVE-2008-4762

    Last Modified: 28 Jun 2018

    Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service crash) and potentially execute arbitrary code via a long argument to the (1) rename and (2) realpath parameters.

    Source:Jeremy Brown
    Published:28 Oct 2008
    4.3
    Medium

    CVE-2008-4761

    Last Modified: 26 Mar 2014

    Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue is probably in the HTMLArea HTMLTidy (HTML Tidy) plugin, not eSupport.

    Source:ShockShadow
    Published:28 Oct 2008
    6.8
    Medium

    CVE-2008-4760

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Vrs-hCk
    Published:28 Oct 2008
    5
    Medium

    CVE-2008-4759

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local files via a .. (dot dot) in the id parameter.

    Source:b3hz4d
    Published:28 Oct 2008
    5
    Medium

    CVE-2008-4758

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local files via a .. (dot dot) in the fichier parameter.

    Source:0xFFFFFF
    Published:28 Oct 2008
    7.5
    High

    CVE-2008-4757

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) add_postit.php (b) delete.php, and (c) mod_prest_date.php; and the (2) prev parameter to (d) prest_detail.php.

    Source:0xFFFFFF
    Published:28 Oct 2008
    4.3
    Medium

    CVE-2008-4756

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary web script or HTML via the date parameter.

    Source:0xFFFFFF
    Published:28 Oct 2008
    7.5
    High

    CVE-2008-4755

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:28 Oct 2008
    5.8
    Medium

    CVE-2008-4754

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.

    Source:Hurley
    Published:27 Oct 2008
    7.5
    High

    CVE-2008-4753

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter.

    Source:yassine_enp
    Published:27 Oct 2008
    7.5
    High

    CVE-2008-4752

    Last Modified: 23 Apr 2026

    TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.

    Source:x0r
    Published:27 Oct 2008
    4.3
    Medium

    CVE-2008-4751

    Last Modified: 26 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597.

    Source:Ghost Hacker
    Published:27 Oct 2008
    9.3
    Critical

    CVE-2008-4750

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote attackers to execute arbitrary code via a long LogFile property.

    Source:shinnai
    Published:27 Oct 2008
    9.3
    Critical

    CVE-2008-4749

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.

    Source:shinnai
    Published:27 Oct 2008
    7.6
    High

    CVE-2008-4748

    Last Modified: 23 Apr 2026

    Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC URIs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the irc:// URI.

    Source:LiquidWorm
    Published:27 Oct 2008
    7.5
    High

    CVE-2008-4744

    Last Modified: 16 Mar 2014

    SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:Hussin X
    Published:27 Oct 2008
    7.5
    High

    CVE-2008-4743

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in index.php in QuidaScript FAQ Management Script allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Hussin X
    Published:27 Oct 2008