4.3
    Medium

    CVE-2008-4742

    Last Modified: 16 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) password and (2) user_name parameters.

    Source:Doz
    Published:27 Oct 2008
    5
    Medium

    CVE-2008-4741

    Last Modified: 16 Mar 2014

    Directory traversal vulnerability in index.php in FAR-PHP 1.00, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.

    Source:Beenu Arora
    Published:27 Oct 2008
    5.1
    Medium

    CVE-2008-4740

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the config[template] parameter.

    Source:cOndemned
    Published:27 Oct 2008
    6.8
    Medium

    CVE-2008-4739

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the navi parameter.

    Source:dun
    Published:24 Oct 2008
    7.5
    High

    CVE-2008-4738

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:r45c4l
    Published:24 Oct 2008
    4.3
    Medium

    CVE-2008-4737

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in wholite.cgi in WhoDomLite 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the dom parameter.

    Source:Ghost Hacker
    Published:24 Oct 2008
    7.5
    High

    CVE-2008-4736

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the showtopic parameter.

    Source:0x90
    Published:24 Oct 2008
    8.5
    High

    CVE-2008-4735

    Last Modified: 23 Dec 2016

    PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter.

    Source:DaRkLiFe
    Published:24 Oct 2008
    7.5
    High

    CVE-2008-4732

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Source:g30rg3_x
    Published:24 Oct 2008
    6.8
    Medium

    CVE-2008-4729

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.

    Source:Thomas Pollet
    Published:23 Oct 2008
    9.3
    Critical

    CVE-2008-4728

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.

    Source:shinnai
    Published:23 Oct 2008
    4.3
    Medium

    CVE-2008-4727

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant from a CSRF vulnerability, but there are insufficient details to be sure.

    Source:Brendan M. Hickey
    Published:23 Oct 2008
    9
    Critical

    CVE-2008-4726

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a long string to the (1) open (aka SSH_FXP_OPEN), (2) unlink, (3) opendir, and other unspecified parameters.

    Source:r0ut3r
    Published:23 Oct 2008
    4.3
    Medium

    CVE-2008-4725

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly escaped before storage in the History Search database (aka md.dat), a different vector than CVE-2008-4696. NOTE: some of these issues were addressed before 9.60.

    Source:Roberto Suggi Liverani
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4721

    Last Modified: 23 Apr 2026

    PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged."

    Source:Crackers_Child
    Published:23 Oct 2008
    9.3
    Critical

    CVE-2008-4720

    Last Modified: 23 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php.

    Source:ZoRLu
    Published:23 Oct 2008
    9.3
    Critical

    CVE-2008-4719

    Last Modified: 23 Dec 2016

    PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter, a different vector than CVE-2008-4329.

    Source:Crackers_Child
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4718

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the help_file parameter, a different vector than CVE-2006-2156.

    Source:NoGe
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4717

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Source:Hussin X
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4716

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:InjEctOr5
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4715

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

    Source:His0k4
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4714

    Last Modified: 23 Dec 2016

    Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.

    Source:Stack
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4713

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands via the qID parameter.

    Source:CWH Underground
    Published:23 Oct 2008
    6.8
    Medium

    CVE-2008-4712

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in pages/showblog.php in LnBlog 0.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the plugin parameter.

    Source:dun
    Published:23 Oct 2008
    6.8
    Medium

    CVE-2008-4711

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.

    Source:~!Dok_tOR!~
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4709

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:S.W.A.T.
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4708

    Last Modified: 23 Apr 2026

    BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.

    Source:Stack
    Published:23 Oct 2008
    5
    Medium

    CVE-2008-4707

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directories via a .. (dot dot) in the lien_2 parameter.

    Source:JIKO
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4706

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.

    Source:elusiven
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4705

    Last Modified: 28 Dec 2016

    SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hakxer
    Published:23 Oct 2008
    10
    Critical

    CVE-2008-4704

    Last Modified: 2 Jan 2017

    PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.

    Source:DaRkLiFe
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4703

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.

    Source:Crackers_Child
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4702

    Last Modified: 23 Dec 2016

    Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) user[language] and (2) user[template] parameters to (a) init.inc.php, and (b) the user[language] parameter to isadmin.inc.php.

    Source:Khashayar Fereidani
    Published:22 Oct 2008
    6.8
    Medium

    CVE-2008-4701

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_user cookie parameter, a different vector than CVE-2008-4700. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:StAkeR
    Published:22 Oct 2008
    6.8
    Medium

    CVE-2008-4700

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in Libera CMS 1.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the libera_staff_pass cookie parameter.

    Source:StAkeR
    Published:22 Oct 2008
    9.3
    Critical

    CVE-2008-4699

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.

    Source:Jeremy Brown
    Published:22 Oct 2008
    4.3
    Medium

    CVE-2008-4696

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).

    Source:egypt
    Published:23 Oct 2008
    9.3
    Critical

    CVE-2008-4694

    Last Modified: 24 Mar 2014

    Unspecified vulnerability in Opera before 9.60 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a redirect that specifies a crafted URL.

    Source:MATASANOS
    Published:23 Oct 2008
    9
    Critical

    CVE-2008-4687

    Last Modified: 8 Jun 2018

    manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.

    Source:Metasploit
    Published:22 Oct 2008
    9.3
    Critical

    CVE-2008-4686

    Last Modified: 23 Nov 2016

    Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.

    Source:Guido Landi
    Published:22 Oct 2008
    5
    Medium

    CVE-2008-4682

    Last Modified: 23 Apr 2026

    wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.

    Source:Shinnok
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4675

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Source:StAkeR
    Published:22 Oct 2008
    6.8
    Medium

    CVE-2008-4674

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.

    Source:CraCkEr
    Published:22 Oct 2008
    10
    Critical

    CVE-2008-4673

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the (1) path[docroot] and (2) component parameters.

    Source:k3vin mitnick
    Published:22 Oct 2008
    4.3
    Medium

    CVE-2008-4672

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in search_results.php in buymyscripts Lyrics Script allows remote attackers to inject arbitrary web script or HTML via the k parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ghost Hacker
    Published:22 Oct 2008
    4.3
    Medium

    CVE-2008-4671

    Last Modified: 23 Mar 2014

    Cross-site scripting (XSS) vulnerability in wp-admin/wp-blogs.php in Wordpress MU (WPMU) before 2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) s and (2) ip_address parameters.

    Source:Juan Galiana Lara
    Published:22 Oct 2008
    4.3
    Medium

    CVE-2008-4670

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in Ed Pudol Clickbank Portal allows remote attackers to inject arbitrary web script or HTML via the search box. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ghost Hacker
    Published:22 Oct 2008
    4.3
    Medium

    CVE-2008-4669

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in Dan Fletcher Recipe Script allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ghost Hacker
    Published:22 Oct 2008
    9
    Critical

    CVE-2008-4668

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the folder parameter to index.php.

    Source:Cr@zy_King
    Published:22 Oct 2008
    7.5
    High

    CVE-2008-4667

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the rss parameter.

    Source:JIKO
    Published:22 Oct 2008