4.3
    Medium

    CVE-2008-4582

    Last Modified: 24 Mar 2014

    Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

    Source:Liu Die Yu
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4574

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Source:Crackers_Child
    Published:15 Oct 2008
    7.5
    High

    CVE-2008-4573

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Source:LUPUS
    Published:15 Oct 2008
    10
    Critical

    CVE-2008-4572

    Last Modified: 23 Apr 2026

    GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.

    Source:dmnt
    Published:15 Oct 2008
    7.5
    High

    CVE-2008-4570

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Hakxer
    Published:15 Oct 2008
    7.5
    High

    CVE-2008-4569

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Source:Hakxer
    Published:15 Oct 2008
    6.8
    Medium

    CVE-2008-4558

    Last Modified: 23 Nov 2016

    Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.

    Source:Core Security
    Published:14 Oct 2008
    10
    Critical

    CVE-2008-4557

    Last Modified: 25 Oct 2016

    plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.

    Source:Eugene Minaev
    Published:14 Oct 2008
    10
    Critical

    CVE-2008-4556

    Last Modified: 4 Oct 2017

    Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.

    Source:kingcope
    Published:14 Oct 2008
    2.6
    Low

    CVE-2008-4549

    Last Modified: 28 Oct 2016

    The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlideShow method.

    Source:rgod
    Published:14 Oct 2008
    9.3
    Critical

    CVE-2008-4548

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote attackers to execute arbitrary code via a long second argument to the ConnectServer method.

    Source:rgod
    Published:14 Oct 2008
    9.3
    Critical

    CVE-2008-4547

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method.

    Source:rgod
    Published:14 Oct 2008
    4.3
    Medium

    CVE-2008-4546

    Last Modified: 24 Mar 2014

    Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.

    Source:Matthew Dempsky
    Published:2 Oct 2008
    4.3
    Medium

    CVE-2008-4532

    Last Modified: 23 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.

    Source:Ghost Hacker
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4529

    Last Modified: 30 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4) DumbStore.php, (5) Extension.php, (6) FileStore.php, (7) HMAC.php, (8) MemcachedStore.php, (9) Message.php, (10) Nonce.php, (11) SQLStore.php, (12) SReg.php, (13) TrustRoot.php, and (14) URINorm.php in classes/Auth/OpenID/; and (15) XRDS.php, (16) XRI.php and (17) XRIRes.php in classes/Auth/Yadis/.

    Source:NoGe
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4528

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter in an edit action.

    Source:BeyazKurt
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4527

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action. NOTE: some of these details are obtained from third party information.

    Source:boom3rang
    Published:9 Oct 2008
    10
    Critical

    CVE-2008-4526

    Last Modified: 26 Dec 2016

    Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and (6) pages/poll.php.

    Source:SirGod
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4525

    Last Modified: 24 Mar 2014

    SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.

    Source:S_DLA_S
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4524

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.

    Source:StAkeR
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4523

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the user_name parameter.

    Source:StAkeR
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4522

    Last Modified: 26 Dec 2016

    Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the src parameter to (1) listen.php and (2) download.php.

    Source:SirGod
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4521

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.

    Source:boom3rang
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4519

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Fastpublish CMS 1.9999 d allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the target parameter to (1) index2.php and (2) index.php.

    Source:~!Dok_tOR!~
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4518

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbitrary SQL commands via the (1) sprache parameter to index2.php and the (2) artikel parameter to index.php.

    Source:~!Dok_tOR!~
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4517

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in leggi.php in geccBBlite 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Piker
    Published:9 Oct 2008
    7.5
    High

    CVE-2008-4516

    Last Modified: 5 Oct 2017

    SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.

    Source:J0hn.X3r
    Published:9 Oct 2008
    5
    Medium

    CVE-2008-4514

    Last Modified: 23 Apr 2026

    The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value, which triggers an assertion error.

    Source:Jeremy Brown
    Published:9 Oct 2008
    4.9
    Medium

    CVE-2008-4510

    Last Modified: 23 Apr 2026

    Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.

    Source:Defsanguje
    Published:9 Oct 2008
    10
    Critical

    CVE-2008-4509

    Last Modified: 30 Dec 2016

    Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory.

    Source:Pepelux
    Published:9 Oct 2008
    7.8
    High

    CVE-2008-4508

    Last Modified: 24 Mar 2014

    Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file containing a long string. NOTE: this is probably a different vulnerability than CVE-2005-2210.

    Source:Ciph3r
    Published:9 Oct 2008
    10
    Critical

    CVE-2008-4502

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a URL in the DFF_config[dir_include] parameter to (1) DFF_affiliate_client_API.php, (2) DFF_featured_prdt.func.php, (3) DFF_mer.func.php, (4) DFF_mer_prdt.func.php, (5) DFF_paging.func.php, (6) DFF_rss.func.php, and (7) DFF_sku.func.php in include/.

    Source:GoLd_M
    Published:8 Oct 2008
    9
    Critical

    CVE-2008-4501

    Last Modified: 27 Sept 2016

    Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.

    Source:dmnt
    Published:8 Oct 2008
    4
    Medium

    CVE-2008-4500

    Last Modified: 26 Dec 2016

    Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".

    Source:dmnt
    Published:8 Oct 2008
    9.3
    Critical

    CVE-2008-4499

    Last Modified: 24 Mar 2014

    Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) refer parameter to main.php and the (2) file parameter to edit.php.

    Source:Pepelux
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4498

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Mr.SQL
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4497

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.

    Source:d3v1l
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4496

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.

    Source:Mr.SQL
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4495

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.

    Source:Mr.SQL
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4494

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:BazOka-HaCkEr
    Published:8 Oct 2008
    6.8
    Medium

    CVE-2008-4493

    Last Modified: 23 Apr 2026

    Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.

    Source:Nine:Situations:Group
    Published:8 Oct 2008
    7.5
    High

    CVE-2008-4492

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.

    Source:Tec-n0x
    Published:8 Oct 2008
    5.1
    Medium

    CVE-2008-4490

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the userInfo cookie.

    Source:JosS
    Published:8 Oct 2008
    10
    Critical

    CVE-2008-4486

    Last Modified: 26 Dec 2016

    Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.

    Source:Pepelux
    Published:8 Oct 2008
    6.8
    Medium

    CVE-2008-4484

    Last Modified: 23 Apr 2026

    main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.

    Source:Pepelux
    Published:8 Oct 2008
    6.8
    Medium

    CVE-2008-4483

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.

    Source:StAkeR
    Published:8 Oct 2008
    9.3
    Critical

    CVE-2008-4472

    Last Modified: 22 Nov 2017

    The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.

    Source:Nine:Situations:Group
    Published:7 Oct 2008
    9.3
    Critical

    CVE-2008-4471

    Last Modified: 22 Nov 2017

    Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via "..\" sequences in the argument to the SaveAS method.

    Source:Nine:Situations:Group
    Published:7 Oct 2008
    9.3
    Critical

    CVE-2008-4470

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrary code via an M3U playlist file that contains a long absolute pathname.

    Source:fl0 fl0w
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4469

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.

    Source:Stack
    Published:7 Oct 2008