7.5
    High

    CVE-2008-4244

    Last Modified: 23 Dec 2016

    Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.

    Source:Stack
    Published:25 Sept 2008
    7.8
    High

    CVE-2008-4243

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:Luigi Auriemma
    Published:25 Sept 2008
    7.5
    High

    CVE-2008-4241

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie.

    Source:-SmoG-
    Published:25 Sept 2008
    4.6
    Medium

    CVE-2008-4210

    Last Modified: 27 Oct 2017

    fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.

    Source:gat3way
    Published:2 May 2007
    5
    Medium

    CVE-2008-4207

    Last Modified: 23 Apr 2026

    Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: some of these details are obtained from third party information.

    Source:K-159
    Published:24 Sept 2008
    7.5
    High

    CVE-2008-4206

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.

    Source:K-159
    Published:24 Sept 2008
    7.5
    High

    CVE-2008-4205

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. NOTE: some of these details are obtained from third party information.

    Source:K-159
    Published:24 Sept 2008
    7.5
    High

    CVE-2008-4204

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.

    Source:JosS
    Published:24 Sept 2008
    7.5
    High

    CVE-2008-4203

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.

    Source:StAkeR
    Published:24 Sept 2008
    7.5
    High

    CVE-2008-4202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.

    Source:sl4xUz
    Published:24 Sept 2008
    5
    Medium

    CVE-2008-4194

    Last Modified: 8 Sept 2017

    The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug."

    Source:I)ruid
    Published:24 Sept 2008
    10
    Critical

    CVE-2008-4193

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter.

    Source:securfrog
    Published:24 Sept 2008
    6.9
    Medium

    CVE-2008-4192

    Last Modified: 20 Jun 2012

    The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.

    Source:Metasploit
    Published:24 Aug 2008
    4.4
    Medium

    CVE-2008-4190

    Last Modified: 21 Sept 2016

    The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.

    Source:nofame
    Published:24 Aug 2008
    Low

    CVE-2008-4189

    Last Modified: 6 Sept 2017

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1105. Reason: This candidate is a duplicate of CVE-2008-1105. Notes: All CVE users should reference CVE-2008-1105 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Guido Landi
    Published:23 Sept 2008
    4.3
    Medium

    CVE-2008-4187

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Source:r45c4l
    Published:23 Sept 2008
    7.5
    High

    CVE-2008-4186

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:JosS
    Published:23 Sept 2008
    7.5
    High

    CVE-2008-4185

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213.

    Source:JosS
    Published:23 Sept 2008
    5
    Medium

    CVE-2008-4183

    Last Modified: 23 Apr 2026

    IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.

    Source:TheJT
    Published:23 Sept 2008
    6.8
    Medium

    CVE-2008-4181

    Last Modified: 30 Dec 2016

    Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:joker_1
    Published:23 Sept 2008
    4.3
    Medium

    CVE-2008-4179

    Last Modified: 19 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.

    Source:Dr.Crash
    Published:23 Sept 2008
    7.5
    High

    CVE-2008-4178

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Source:Hussin X
    Published:23 Sept 2008
    7.5
    High

    CVE-2008-4177

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:JosS
    Published:23 Sept 2008
    7.5
    High

    CVE-2008-4176

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter.

    Source:Crackers_Child
    Published:23 Sept 2008
    6.5
    Medium

    CVE-2008-4175

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.

    Source:SirGod
    Published:23 Sept 2008
    4.3
    Medium

    CVE-2008-4174

    Last Modified: 19 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters.

    Source:Xylitol
    Published:23 Sept 2008
    7.5
    High

    CVE-2008-4173

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.

    Source:SuNHouSe2
    Published:22 Sept 2008
    7.5
    High

    CVE-2008-4172

    Last Modified: 20 Mar 2014

    SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.

    Source:Hussin X
    Published:22 Sept 2008
    7.5
    High

    CVE-2008-4169

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.

    Source:SirGod
    Published:22 Sept 2008
    6.4
    Medium

    CVE-2008-4167

    Last Modified: 23 Dec 2016

    useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.

    Source:Stack
    Published:22 Sept 2008
    4.3
    Medium

    CVE-2008-4166

    Last Modified: 20 Mar 2014

    Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL encode a string containing many instances of an invalid character.

    Source:0x90
    Published:22 Sept 2008
    2.6
    Low

    CVE-2008-4164

    Last Modified: 23 Apr 2026

    cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Source:Ams
    Published:22 Sept 2008
    6.8
    Medium

    CVE-2008-4161

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.

    Source:Neo Anderson
    Published:22 Sept 2008
    7.5
    High

    CVE-2008-4159

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.

    Source:Cru3l.b0y
    Published:22 Sept 2008
    6.8
    Medium

    CVE-2008-4158

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.

    Source:SirGod
    Published:22 Sept 2008
    7.5
    High

    CVE-2008-4157

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported that 1.2.3 is also affected.

    Source:r45c4l
    Published:22 Sept 2008
    6.8
    Medium

    CVE-2008-4156

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:~!Dok_tOR!~
    Published:19 Sept 2008
    7.8
    High

    CVE-2008-4155

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in the (1) module or (2) action parameter in (a) www/index.php; the (3) module, (4) ss_module, or (5) ss_action parameter in (b) modules/Module/index.php or (c) modules/Themes/index.php; or the (6) module parameter in (d) inc/vmenu.php.

    Source:SirGod
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4154

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.

    Source:Lidloses_Auge
    Published:19 Sept 2008
    5
    Medium

    CVE-2008-4151

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (dot dot) in the neturl parameter.

    Source:xy7
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4150

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.

    Source:SarBoT511
    Published:19 Sept 2008
    5
    Medium

    CVE-2008-4146

    Last Modified: 22 Nov 2017

    Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

    Source:Pepelux
    Published:19 Sept 2008
    6.8
    Medium

    CVE-2008-4145

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:ka0x
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4144

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action.

    Source:Hussin X
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4142

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

    Source:HaCkeR_EgY
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4141

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.

    Source:THUNDER
    Published:19 Sept 2008
    4.3
    Medium

    CVE-2008-4140

    Last Modified: 20 Mar 2014

    Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:John Cobb
    Published:19 Sept 2008
    2.6
    Low

    CVE-2008-4139

    Last Modified: 20 Mar 2014

    Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:John Cobb
    Published:19 Sept 2008
    10
    Critical

    CVE-2008-4138

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.

    Source:webDEViL
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4137

    Last Modified: 23 Dec 2016

    PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter.

    Source:Piker
    Published:19 Sept 2008