4.3
    Medium

    CVE-2008-3676

    Last Modified: 6 Jan 2017

    Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands.

    Source:Antunes
    Published:14 Aug 2008
    5
    Medium

    CVE-2008-3675

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information.

    Source:JIKO
    Published:14 Aug 2008
    7.5
    High

    CVE-2008-3674

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execute arbitrary SQL commands via the UID parameter.

    Source:Hussin X
    Published:13 Aug 2008
    7.5
    High

    CVE-2008-3673

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672.

    Source:Hussin X
    Published:13 Aug 2008
    7.5
    High

    CVE-2008-3672

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Hussin X
    Published:13 Aug 2008
    6.8
    Medium

    CVE-2008-3670

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in authordetail.php in Article Friendly Pro allows remote attackers to execute arbitrary SQL commands via the autid parameter.

    Source:Mr.SQL
    Published:13 Aug 2008
    7.5
    High

    CVE-2008-3669

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Source:Mr.SQL
    Published:13 Aug 2008
    4.3
    Medium

    CVE-2008-3668

    Last Modified: 12 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description field of a new scrap.

    Source:Lostmon
    Published:13 Aug 2008
    6.8
    Medium

    CVE-2008-3667

    Last Modified: 12 Mar 2014

    Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.

    Source:DATA_SNIPER
    Published:13 Aug 2008
    4.3
    Medium

    CVE-2008-3664

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php, (5) the last_name parameter to contacts/some.php, (6) the campaign_title parameter to campaigns/some.php, (7) the opportunity_title parameter to opportunities/some.php, (8) the case_title parameter to cases/some.php, (9) the file_id parameter to files/some.php, or (10) the starting parameter to reports/custom/mileage.php, a related issue to CVE-2008-1129.

    Source:Fabian Fingerle
    Published:5 Sept 2008
    7.5
    High

    CVE-2008-3657

    Last Modified: 21 Dec 2016

    The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-dependent attackers to bypass safe levels and execute dangerous functions by accessing a library using DL.dlopen.

    Source:Keita Yamaguchi
    Published:8 Aug 2008
    7.8
    High

    CVE-2008-3656

    Last Modified: 21 Dec 2016

    Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.

    Source:Keita Yamaguchi
    Published:8 Aug 2008
    7.5
    High

    CVE-2008-3655

    Last Modified: 21 Dec 2016

    Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.

    Source:Keita Yamaguchi
    Published:8 Aug 2008
    6.8
    Medium

    CVE-2008-3649

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in categorydetail.php in Article Friendly Standard allows remote attackers to execute arbitrary SQL commands via the Cat parameter.

    Source:Mr.SQL
    Published:13 Aug 2008
    10
    Critical

    CVE-2008-3641

    Last Modified: 24 Mar 2014

    The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.

    Source:regenrecht
    Published:9 Oct 2008
    5
    Medium

    CVE-2008-3607

    Last Modified: 12 Mar 2014

    The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands.

    Source:Antunes
    Published:12 Aug 2008
    6.5
    Medium

    CVE-2008-3606

    Last Modified: 12 Mar 2014

    Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.

    Source:Antunes
    Published:12 Aug 2008
    9.8
    Critical

    CVE-2008-3604

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Source:Hussin X
    Published:12 Aug 2008
    7.5
    High

    CVE-2008-3603

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sections action.

    Source:CraCkEr
    Published:12 Aug 2008
    7.5
    High

    CVE-2008-3602

    Last Modified: 23 Apr 2026

    admin/wr_admin.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9.1 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

    Source:Virangar Security
    Published:12 Aug 2008
    7.5
    High

    CVE-2008-3601

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action.

    Source:irk4z
    Published:12 Aug 2008
    7.5
    High

    CVE-2008-3599

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:nuclear
    Published:12 Aug 2008
    7.5
    High

    CVE-2008-3598

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the Cid parameter to categories.php or (2) the Username parameter to login.php.

    Source:Virangar Security
    Published:12 Aug 2008
    9.3
    Critical

    CVE-2008-3595

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter.

    Source:CraCkEr
    Published:12 Aug 2008
    7.5
    High

    CVE-2008-3594

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:Mr.SQL
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3593

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:SirGod
    Published:11 Aug 2008
    8.5
    High

    CVE-2008-3592

    Last Modified: 17 Aug 2017

    Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

    Source:Raz0r
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3591

    Last Modified: 17 Aug 2017

    SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.

    Source:Raz0r
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3590

    Last Modified: 4 Jan 2017

    Multiple SQL injection vulnerabilities in admin/login.asp in E. Z. Poll 2 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:t0fx
    Published:11 Aug 2008
    4.3
    Medium

    CVE-2008-3589

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.

    Source:Ams
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3588

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.

    Source:cOndemned
    Published:11 Aug 2008
    4.3
    Medium

    CVE-2008-3587

    Last Modified: 10 Mar 2014

    Cross-site scripting (XSS) vulnerability in result.php in Chris Bunting Homes 4 Sale allows remote attackers to inject arbitrary web script or HTML via the r parameter.

    Source:Ghost Hacker
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3586

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:His0k4
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3585

    Last Modified: 15 Dec 2016

    Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) product_desc.php and (2) store_info.php.

    Source:Hussin X
    Published:11 Aug 2008
    7.5
    High

    CVE-2008-3583

    Last Modified: 23 Apr 2026

    Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an IMG element. NOTE: this might be related to CVE-2008-3360. NOTE: it was later reported that 2.08 Beta 4 is also affected.

    Source:r0ut3r
    Published:10 Aug 2008
    6.8
    Medium

    CVE-2008-3582

    Last Modified: 10 Mar 2014

    SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:crimsoN_Loyd9
    Published:10 Aug 2008
    4.3
    Medium

    CVE-2008-3581

    Last Modified: 17 Nov 2016

    Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web script or HTML via the login_message parameter in a login action.

    Source:Corwin
    Published:10 Aug 2008
    7.5
    High

    CVE-2008-3580

    Last Modified: 17 Nov 2016

    Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.

    Source:Corwin
    Published:10 Aug 2008
    5
    Medium

    CVE-2008-3578

    Last Modified: 15 Dec 2016

    HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI.

    Source:securfrog
    Published:10 Aug 2008
    7.5
    High

    CVE-2008-3575

    Last Modified: 7 Mar 2014

    PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[gsLanguage] parameter, a different vector than CVE-2006-4477 and CVE-2004-0132.

    Source:HACKERS PAL
    Published:10 Aug 2008
    2.6
    Low

    CVE-2008-3574

    Last Modified: 13 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) lang_install22, (4) titelkop, (5) lang_kop1, (6) lang_kop2, (7) lang_modules, (8) lang_kop4, (9) lang_kop15, (10) lang_kop5, and (11) titelkop parameters to (b) data/inc/header.php; the pluck_version and titelkop parameters to (c) data/inc/header2.php; and the (14) lang_theme6 parameter to (d) data/inc/themeinstall.php.

    Source:Khashayar Fereidani
    Published:10 Aug 2008
    5
    Medium

    CVE-2008-3573

    Last Modified: 5 Jan 2017

    The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.

    Source:Micheal Brooks
    Published:10 Aug 2008
    7.8
    High

    CVE-2008-3571

    Last Modified: 23 Apr 2026

    The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.

    Source:crit3rion
    Published:10 Aug 2008
    7.5
    High

    CVE-2008-3570

    Last Modified: 15 Dec 2016

    PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in the abg_path parameter.

    Source:Lo$er
    Published:10 Aug 2008
    4.3
    Medium

    CVE-2008-3569

    Last Modified: 11 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the text parameter to (1) iart.php and (2) ming.php.

    Source:Khashayar Fereidani
    Published:10 Aug 2008
    7.5
    High

    CVE-2008-3568

    Last Modified: 10 Mar 2014

    Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UNAK-CMS 1.5.5 allows remote attackers to include and execute arbitrary local files via a full pathname in the Dirroot parameter, a different vulnerability than CVE-2006-4890.1.

    Source:Sina Yazdanmehr
    Published:10 Aug 2008
    4.3
    Medium

    CVE-2008-3566

    Last Modified: 10 Mar 2014

    Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ahmadbady
    Published:10 Aug 2008
    4.3
    Medium

    CVE-2008-3565

    Last Modified: 2 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:sl4xUz
    Published:10 Aug 2008
    7.5
    High

    CVE-2008-3564

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p, (2) cat, and (3) archive parameters. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:Virangar Security
    Published:10 Aug 2008
    7.5
    High

    CVE-2008-3563

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the activate parameter to admin/plog-themes.php, related to theme_dir settings.

    Source:GulfTech Security
    Published:10 Aug 2008