5
    Medium

    CVE-2008-4136

    Last Modified: 23 Apr 2026

    Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames.

    Source:Shinnok
    Published:19 Sept 2008
    7.8
    High

    CVE-2008-4135

    Last Modified: 23 Apr 2026

    Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames.

    Source:wins.mallow
    Published:19 Sept 2008
    7.5
    High

    CVE-2008-4134

    Last Modified: 23 Dec 2016

    PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter.

    Source:ka0x
    Published:19 Sept 2008
    4.3
    Medium

    CVE-2008-4133

    Last Modified: 18 Mar 2014

    The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters.

    Source:Marc Ruef
    Published:19 Sept 2008
    7.2
    High

    CVE-2008-4131

    Last Modified: 20 Mar 2014

    Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.

    Source:Eli the Bearded
    Published:19 Sept 2008
    4.3
    Medium

    CVE-2008-4128

    Last Modified: 13 Jul 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

    Source:Jeremy Brown
    Published:18 Sept 2008
    4.3
    Medium

    CVE-2008-4120

    Last Modified: 21 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) pass parameter to login.php, or the (3) name parameter to contact.php.

    Source:Fabian Fingerle
    Published:29 Sept 2008
    9.3
    Critical

    CVE-2008-4116

    Last Modified: 27 Oct 2016

    Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that leads to a heap-based buffer overflow.

    Source:securfrog
    Published:17 Sept 2008
    5
    Medium

    CVE-2008-4115

    Last Modified: 23 Apr 2026

    TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.

    Source:SirGod
    Published:16 Sept 2008
    7.1
    High

    CVE-2008-4114

    Last Modified: 23 Apr 2026

    srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."

    Source:Javier Vicente Vallejo
    Published:16 Sept 2008
    4.7
    Medium

    CVE-2008-4113

    Last Modified: 23 Apr 2026

    The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.

    Source:Jon Oberheide
    Published:21 Aug 2008
    Low

    CVE-2008-4112

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3195. Reason: This candidate is a duplicate of CVE-2008-3195. Notes: All CVE users should reference CVE-2008-3195 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Th1nk3r
    Published:16 Sept 2008
    5
    Medium

    CVE-2008-4109

    Last Modified: 23 Apr 2026

    A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal handler for login timeouts, which allows remote attackers to cause a denial of service (connection slot exhaustion) via multiple login attempts. NOTE: this issue exists because of an incorrect fix for CVE-2006-5051.

    Published:17 Sept 2008
    9.3
    Critical

    CVE-2008-4101

    Last Modified: 16 Mar 2014

    Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

    Source:Ben Schmidt
    Published:22 Aug 2008
    8.5
    High

    CVE-2008-4096

    Last Modified: 20 Mar 2014

    libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrary code via a request to server_databases.php with a sort_by parameter containing PHP sequences, which are processed by create_function.

    Source:Norman Hippert
    Published:17 Sept 2008
    6.8
    Medium

    CVE-2008-4093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Source:~!Dok_tOR!~
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4092

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.

    Source:MustLive
    Published:15 Sept 2008
    6.8
    Medium

    CVE-2008-4091

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.

    Source:Hussin X
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4090

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an addtocart action, a different vector than CVE-2007-2672.

    Source:Hussin X
    Published:15 Sept 2008
    4.3
    Medium

    CVE-2008-4089

    Last Modified: 23 Dec 2016

    Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

    Source:MustLive
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4088

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Source:MustLive
    Published:15 Sept 2008
    6.8
    Medium

    CVE-2008-4087

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code via a Beatcraft Project (aka bcproj) file with a long string in a certain instruments title field.

    Source:Koshi
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4086

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.

    Source:Hussin X
    Published:15 Sept 2008
    6.8
    Medium

    CVE-2008-4084

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.

    Source:e.wiZz!
    Published:15 Sept 2008
    3.5
    Low

    CVE-2008-4083

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action to index.php. NOTE: some of these details are obtained from third party information.

    Source:InjEctOr5
    Published:15 Sept 2008
    4.6
    Medium

    CVE-2008-4082

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php.

    Source:InjEctOr5
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4081

    Last Modified: 23 Dec 2016

    admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.

    Source:Ciph3r
    Published:15 Sept 2008
    6.8
    Medium

    CVE-2008-4080

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these details are obtained from third party information.

    Source:Khashayar Fereidani
    Published:15 Sept 2008
    6.8
    Medium

    CVE-2008-4075

    Last Modified: 22 Dec 2016

    Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.

    Source:SirGod
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4074

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:ZoRLu
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4073

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action.

    Source:ZoRLu
    Published:15 Sept 2008
    7.5
    High

    CVE-2008-4072

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.

    Source:Khashayar Fereidani
    Published:15 Sept 2008
    5
    Medium

    CVE-2008-4071

    Last Modified: 23 Apr 2026

    A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.

    Source:Jeremy Brown
    Published:15 Sept 2008
    4.3
    Medium

    CVE-2008-4056

    Last Modified: 20 Dec 2016

    Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Sam Georgiou
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-4055

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.

    Source:Hussin X
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-4054

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Kacak
    Published:11 Sept 2008
    4.3
    Medium

    CVE-2008-4053

    Last Modified: 16 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.

    Source:Lostmon
    Published:11 Sept 2008
    4.3
    Medium

    CVE-2008-4051

    Last Modified: 16 Mar 2014

    Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Bug Researchers Group
    Published:11 Sept 2008
    9.3
    Critical

    CVE-2008-4050

    Last Modified: 23 Apr 2026

    A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.

    Source:spdr
    Published:11 Sept 2008
    6.8
    Medium

    CVE-2008-4049

    Last Modified: 23 Apr 2026

    A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method.

    Source:spdr
    Published:11 Sept 2008
    6.8
    Medium

    CVE-2008-4048

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method.

    Source:spdr
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-4046

    Last Modified: 17 Mar 2014

    SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:e.wiZz!
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-4044

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter.

    Source:InjEctOr5
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-4043

    Last Modified: 29 Nov 2016

    Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php.

    Source:security fears team
    Published:11 Sept 2008
    Low

    CVE-2008-4042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3889. Reason: This candidate is a duplicate of CVE-2008-3889. Notes: All CVE users should reference CVE-2008-3889 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Albert Sellares
    Published:11 Sept 2008
    4
    Medium

    CVE-2008-4041

    Last Modified: 17 Mar 2014

    The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters.

    Source:Antunes
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-4039

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.

    Source:InjEctOr5
    Published:11 Sept 2008
    9.3
    Critical

    CVE-2008-4037

    Last Modified: 7 Mar 2011

    Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.

    Source:Metasploit
    Published:12 Nov 2008
    4.3
    Medium

    CVE-2008-4033

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

    Source:Jerome Athias
    Published:12 Nov 2008
    4.3
    Medium

    CVE-2008-4029

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka "MSXML DTD Cross-Domain Scripting Vulnerability."

    Source:Jerome Athias
    Published:12 Nov 2008