7.5
    High

    CVE-2008-4371

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the aIDS parameter.

    Source:sl4xUz
    Published:1 Oct 2008
    4.3
    Medium

    CVE-2008-4370

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php.

    Source:sl4xUz
    Published:1 Oct 2008
    7.5
    High

    CVE-2008-4369

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Source:sl4xUz
    Published:1 Oct 2008
    6.5
    Medium

    CVE-2008-4366

    Last Modified: 21 Dec 2016

    Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a user directory under images/photos/upload.

    Source:Mi4night
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4364

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the "page" page and (2) txtSearch parameter in the "Search" page.

    Source:BugReport.IR
    Published:30 Sept 2008
    7.2
    High

    CVE-2008-4363

    Last Modified: 23 Apr 2026

    DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, probably related to use of the ProbeForRead function when ProbeForWrite was intended.

    Source:mu-b
    Published:30 Sept 2008
    4.9
    Medium

    CVE-2008-4362

    Last Modified: 23 Apr 2026

    The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWalter0.

    Source:NT Internals
    Published:30 Sept 2008
    7.8
    High

    CVE-2008-4361

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the path parameter to the default URI.

    Source:r45c4l
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4357

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Stack
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4356

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid parameter to index.php in a Result action to the Voting module; (3) the fid parameter to index.php in a ShowForum action to the Forum module; (4) the tid parameter to index.php in a ShowTopic action to the Forum module; (5) the uname parameter to index.php in a UserInfo action to the Account module; or (6) the module parameter to index.php, probably related to the TopSites module.

    Source:~!Dok_tOR!~
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4355

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:tmh
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4354

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.

    Source:r45c4l
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4353

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: although one component of Linkarity is distributable PHP code, this issue might be site-specific. If so, it should not be included in CVE.

    Source:Egypt Coder
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4352

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a viewprofile action to index.php.

    Source:r3dm0v3
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4351

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the p parameter.

    Source:r3dm0v3
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4350

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:FIREH4CK3R
    Published:30 Sept 2008
    4.3
    Medium

    CVE-2008-4349

    Last Modified: 19 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) page parameter in a details action.

    Source:Xylitol
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4347

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Source:r45c4l
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4346

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.

    Source:SirGod
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4345

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.

    Source:StAkeR
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4344

    Last Modified: 21 Mar 2014

    SQL injection vulnerability in cat.php in 6rbScript allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

    Source:Karar Alshami
    Published:30 Sept 2008
    9.3
    Critical

    CVE-2008-4343

    Last Modified: 23 Apr 2026

    The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

    Source:shinnai
    Published:30 Sept 2008
    9.3
    Critical

    CVE-2008-4342

    Last Modified: 22 Nov 2017

    NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

    Source:Nine:Situations:Group
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4341

    Last Modified: 23 Apr 2026

    add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin.

    Source:Pepelux
    Published:30 Sept 2008
    4.3
    Medium

    CVE-2008-4340

    Last Modified: 30 Oct 2016

    Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a carriage return ("\r\n\r\n") argument to the window.open function.

    Source:Aditya K Sood
    Published:30 Sept 2008
    4.3
    Medium

    CVE-2008-4336

    Last Modified: 23 Dec 2016

    Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter.

    Source:d3v1l
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4335

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.

    Source:Stack
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4334

    Last Modified: 23 Apr 2026

    PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

    Source:Stack
    Published:30 Sept 2008
    4.3
    Medium

    CVE-2008-4333

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.

    Source:CWH Underground
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4332

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php.

    Source:CWH Underground
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4331

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to index.php.

    Source:dun
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4330

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the design parameter.

    Source:dun
    Published:30 Sept 2008
    10
    Critical

    CVE-2008-4329

    Last Modified: 23 Dec 2016

    PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter.

    Source:dun
    Published:30 Sept 2008
    7.5
    High

    CVE-2008-4328

    Last Modified: 21 Mar 2014

    SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL commands via the (1) item, (2) search_ordermethod, and (3) search_order parameters.

    Source:David Sopas
    Published:30 Sept 2008
    4.3
    Medium

    CVE-2008-4327

    Last Modified: 23 Apr 2026

    gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows user-assisted attackers to cause a denial of service (divide-by-zero error and persistent application crash) via this crash.ico file on the desktop, a different vulnerability than CVE-2007-2237.

    Source:laurent gaffié
    Published:30 Sept 2008
    5
    Medium

    CVE-2008-4324

    Last Modified: 23 Dec 2016

    The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

    Source:Aditya K Sood
    Published:29 Sept 2008
    4.3
    Medium

    CVE-2008-4323

    Last Modified: 23 Apr 2026

    Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file.

    Source:fl0 fl0w
    Published:29 Sept 2008
    10
    Critical

    CVE-2008-4322

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote attackers to execute arbitrary code via a crafted FC_INFOTAG/SET_CONTROL packet.

    Source:Metasploit
    Published:29 Sept 2008
    9.3
    Critical

    CVE-2008-4321

    Last Modified: 20 Dec 2016

    Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command.

    Source:h07
    Published:29 Sept 2008
    4.3
    Medium

    CVE-2008-4320

    Last Modified: 26 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary web script or HTML via (1) the j_username parameter to j_acegi_security_check, (2) the username parameter to notification/list.jsp, and (3) the filter parameter to event/list.

    Source:d2d
    Published:29 Sept 2008
    6.4
    Medium

    CVE-2008-4319

    Last Modified: 23 Dec 2016

    fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.

    Source:Pepelux
    Published:29 Sept 2008
    10
    Critical

    CVE-2008-4318

    Last Modified: 23 Apr 2026

    Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.

    Source:dun
    Published:29 Sept 2008
    7.8
    High

    CVE-2008-4310

    Last Modified: 21 Dec 2016

    httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.

    Source:Keita Yamaguchi
    Published:4 Dec 2008
    5.5
    Medium

    CVE-2008-4302

    Last Modified: 20 Mar 2014

    fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.

    Source:Jens Axboe
    Published:20 Jul 2007
    5.4
    Medium

    CVE-2008-4295

    Last Modified: 23 Apr 2026

    Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.

    Source:Julien Bedard
    Published:27 Sept 2008
    Low

    CVE-2008-4270

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5416. Reason: This candidate is a duplicate of CVE-2008-5416. Notes: All CVE users should reference CVE-2008-5416 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Guido Landi
    Published:30 Dec 2008
    9.3
    Critical

    CVE-2008-4255

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."

    Source:Jerome Athias
    Published:10 Dec 2008
    9.8
    Critical

    CVE-2008-4250

    Last Modified: 20 May 2026

    The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

    Source:stephen lawler
    Published:23 Oct 2008
    7.5
    High

    CVE-2008-4247

    Last Modified: 21 Mar 2014

    ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.

    Source:Maksymilian Arciemowicz
    Published:25 Sept 2008
    6.5
    Medium

    CVE-2008-4245

    Last Modified: 23 Dec 2016

    The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.

    Source:CWH Underground
    Published:25 Sept 2008