7.5
    High

    CVE-2008-4468

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:DeViL iRaQ
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4467

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:DeViL iRaQ
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4466

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:Stack
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4465

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:DeViL iRaQ
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4464

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:Stack
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4463

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Source:Stack
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4462

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Source:DeViL iRaQ
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4461

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.

    Source:ZoRLu
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4460

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter.

    Source:Stack
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4459

    Last Modified: 18 Mar 2014

    SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information.

    Source:Omer Singer
    Published:7 Oct 2008
    7.5
    High

    CVE-2008-4458

    Last Modified: 19 Mar 2014

    SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.

    Source:r45c4l
    Published:7 Oct 2008
    6.8
    Medium

    CVE-2008-4457

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.

    Source:Ams
    Published:7 Oct 2008
    2.6
    Low

    CVE-2008-4456

    Last Modified: 23 Mar 2014

    Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by placing it in a database cell, which might be accessed by this client when composing an HTML document. NOTE: as of 20081031, the issue has not been fixed in MySQL 5.0.67.

    Source:Thomas Henlich
    Published:30 Sept 2008
    6.8
    Medium

    CVE-2008-4455

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the language cookie.

    Source:JosS
    Published:6 Oct 2008
    6.8
    Medium

    CVE-2008-4454

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the lang parameter to actions.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:JosS
    Published:6 Oct 2008
    9.3
    Critical

    CVE-2008-4453

    Last Modified: 23 Apr 2026

    The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

    Source:EgiX
    Published:6 Oct 2008
    9
    Critical

    CVE-2008-4452

    Last Modified: 23 Dec 2016

    Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly execute arbitrary code via a long CWD request.

    Source:Julien Bedard
    Published:6 Oct 2008
    7.2
    High

    CVE-2008-4451

    Last Modified: 23 Apr 2026

    The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer.

    Source:NT Internals
    Published:6 Oct 2008
    9.3
    Critical

    CVE-2008-4449

    Last Modified: 29 Nov 2013

    Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.

    Source:securfrog
    Published:6 Oct 2008
    4.3
    Medium

    CVE-2008-4447

    Last Modified: 23 Mar 2014

    Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.

    Source:C1c4Tr1Z
    Published:6 Oct 2008
    10
    Critical

    CVE-2008-4439

    Last Modified: 13 Mar 2014

    PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Bug Researchers Group
    Published:3 Oct 2008
    4.3
    Medium

    CVE-2008-4438

    Last Modified: 13 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Bug Researchers Group
    Published:3 Oct 2008
    7.1
    High

    CVE-2008-4437

    Last Modified: 13 Mar 2014

    Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

    Source:ilja van sprundel
    Published:3 Oct 2008
    7.5
    High

    CVE-2008-4436

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter.

    Source:IP-Sh0k
    Published:3 Oct 2008
    4.3
    Medium

    CVE-2008-4435

    Last Modified: 13 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.

    Source:Lostmon
    Published:3 Oct 2008
    9.3
    Critical

    CVE-2008-4434

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.

    Source:Guido Landi
    Published:3 Oct 2008
    4.3
    Medium

    CVE-2008-4432

    Last Modified: 12 Mar 2014

    Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.

    Source:Lostmon
    Published:3 Oct 2008
    10
    Critical

    CVE-2008-4428

    Last Modified: 30 Dec 2016

    Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.

    Source:BeyazKurt
    Published:3 Oct 2008
    7.5
    High

    CVE-2008-4427

    Last Modified: 30 Dec 2016

    changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.

    Source:BeyazKurt
    Published:3 Oct 2008
    4.3
    Medium

    CVE-2008-4426

    Last Modified: 30 Dec 2016

    Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action.

    Source:BeyazKurt
    Published:3 Oct 2008
    8.8
    High

    CVE-2008-4425

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action.

    Source:BeyazKurt
    Published:3 Oct 2008
    4.3
    Medium

    CVE-2008-4424

    Last Modified: 13 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in Domain Group Network GooCMS 1.02 allows remote attackers to inject arbitrary web script or HTML via the s parameter in a comments action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ahmadbaby
    Published:3 Oct 2008
    6.5
    Medium

    CVE-2008-4423

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a contact modify action.

    Source:Khashayar Fereidani
    Published:3 Oct 2008
    7.8
    High

    CVE-2008-4421

    Last Modified: 6 Oct 2017

    Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL.

    Source:Brad Antoniewicz
    Published:7 Oct 2008
    5
    Medium

    CVE-2008-4409

    Last Modified: 23 Mar 2014

    libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

    Source:Christian Weiske
    Published:2 Oct 2008
    7.2
    High

    CVE-2008-4405

    Last Modified: 23 Mar 2014

    xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's write access within this tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue was originally reported as an issue in libvirt 0.3.3 and xenstore, but CVE is considering the core issue to be related to Xen.

    Source:Pascal Bouchareine
    Published:30 Sept 2008
    10
    Critical

    CVE-2008-4397

    Last Modified: 10 Mar 2011

    Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.

    Source:Metasploit
    Published:14 Oct 2008
    4.3
    Medium

    CVE-2008-4393

    Last Modified: 24 Mar 2014

    Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to zodiac/servlet/zodiac.

    Source:Mazin Faour
    Published:7 Oct 2008
    9.3
    Critical

    CVE-2008-4388

    Last Modified: 10 Mar 2011

    The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.

    Source:Metasploit
    Published:20 Jan 2009
    9.3
    Critical

    CVE-2008-4385

    Last Modified: 10 Mar 2011

    Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary programs via by specifiying a malicious website argument to the Init method in (1) a certain ActiveX control (sysreqlab2.cab, sysreqlab.dll, sysreqlabsli.dll, or sysreqlab2.dll) and (2) a certain Java applet in RLApplet.class in sysreqlab2.jar or sysreqlab.jar.

    Source:Metasploit
    Published:14 Oct 2008
    9.3
    Critical

    CVE-2008-4384

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.

    Source:Metasploit
    Published:7 Oct 2008
    7.8
    High

    CVE-2008-4380

    Last Modified: 23 Apr 2026

    The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the filter for configuration properties and "/x" characters.

    Source:Alex Hernandez
    Published:1 Oct 2008
    4.3
    Medium

    CVE-2008-4379

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:sl4xUz
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4378

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:sl4xUz
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4377

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.

    Source:ThE X-HaCkEr
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4376

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Source:InjEctOr5
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4375

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Source:Stack
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4374

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the id parameter in a playgame action.

    Source:security fears team
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4373

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter.

    Source:InjEctOr5
    Published:1 Oct 2008
    4.3
    Medium

    CVE-2008-4372

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter.

    Source:sl4xUz
    Published:1 Oct 2008