5.1
    Medium

    CVE-2008-3562

    Last Modified: 11 Mar 2014

    Directory traversal vulnerability in index.php in the Contact module in Chupix CMS 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mods parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:casper41
    Published:10 Aug 2008
    6.8
    Medium

    CVE-2008-3561

    Last Modified: 11 Mar 2014

    SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.

    Source:Rohit Bansal
    Published:10 Aug 2008
    4.3
    Medium

    CVE-2008-3560

    Last Modified: 12 Mar 2014

    Cross-site scripting (XSS) vulnerability in kshop_search.php in the Kshop module 2.22 for Xoops allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Lostmon
    Published:8 Aug 2008
    4.3
    Medium

    CVE-2008-3559

    Last Modified: 12 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice allow remote attackers to inject arbitrary web script or HTML via the (1) filename parameter to search.asp and the (2) page parameter to order.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:by_casper41
    Published:8 Aug 2008
    9.3
    Critical

    CVE-2008-3558

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.

    Source:Metasploit
    Published:8 Aug 2008
    7.5
    High

    CVE-2008-3557

    Last Modified: 23 Apr 2026

    Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and loggedin cookies.

    Source:Scary-Boys
    Published:8 Aug 2008
    7.5
    High

    CVE-2008-3556

    Last Modified: 2 Dec 2016

    Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action. NOTE: vector 1 might be the same as CVE-2008-2522.

    Source:Khashayar Fereidani
    Published:8 Aug 2008
    6.8
    Medium

    CVE-2008-3555

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the TID parameter, as demonstrated by uploading a .jpg file containing PHP sequences.

    Source:otmorozok428
    Published:8 Aug 2008
    7.5
    High

    CVE-2008-3554

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.

    Source:james
    Published:8 Aug 2008
    9
    Critical

    CVE-2008-3544

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.

    Source:Luigi Auriemma
    Published:13 Oct 2008
    10
    Critical

    CVE-2008-3533

    Last Modified: 14 Mar 2014

    Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to execute arbitrary code via format string specifiers in an invalid URI on the command line, as demonstrated by use of yelp within (1) man or (2) ghelp URI handlers in Firefox, Evolution, and unspecified other programs.

    Source:Aaron Grattafiori
    Published:11 Aug 2008
    6.9
    Medium

    CVE-2008-3531

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data" in "certain error conditions."

    Source:Patroklos Argyroudis
    Published:5 Sept 2008
    10
    Critical

    CVE-2008-3529

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

    Source:Kevin Finisterre
    Published:11 Sept 2008
    7.5
    High

    CVE-2008-3513

    Last Modified: 10 Mar 2014

    SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.

    Source:H4ckCity Security Team
    Published:7 Aug 2008
    7.5
    High

    CVE-2008-3512

    Last Modified: 12 Mar 2014

    SQL injection vulnerability in the Kleinanzeigen module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the lid parameter in a visit action to modules.php.

    Source:Lovebug
    Published:7 Aug 2008
    4.3
    Medium

    CVE-2008-3511

    Last Modified: 11 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php, and suggest_image.php, and (e) index.php, (f) adminhome.php, (g) config.php, (h) changepassword.php, (i) cleanup.php, (j) browsecats.php, and (k) images.php in admin/. NOTE: the image_desc.php/msg vector is covered by CVE-2006-1660. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:sl4xUz
    Published:7 Aug 2008
    4.3
    Medium

    CVE-2008-3510

    Last Modified: 11 Mar 2014

    Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter.

    Source:CoRSaNTuRK
    Published:7 Aug 2008
    7.5
    High

    CVE-2008-3509

    Last Modified: 26 Dec 2010

    LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

    Source:PoMdaPiMp
    Published:7 Aug 2008
    5
    Medium

    CVE-2008-3508

    Last Modified: 23 Apr 2026

    LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.

    Source:Scary-Boys
    Published:7 Aug 2008
    7.5
    High

    CVE-2008-3507

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

    Source:Stack
    Published:7 Aug 2008
    7.5
    High

    CVE-2008-3506

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands via the nr parameter to the default URI.

    Source:CWH Underground
    Published:6 Aug 2008
    4.3
    Medium

    CVE-2008-3505

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via the nr parameter to the default URI.

    Source:CWH Underground
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3498

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the nBill (com_netinvoice) component 1.2.0 SP1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in an orders action to index.php. NOTE: some of these details are obtained from third party information.

    Source:His0k4
    Published:6 Aug 2008
    6.8
    Medium

    CVE-2008-3497

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:CWH Underground
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3495

    Last Modified: 10 Mar 2014

    SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands via the kid parameter.

    Source:U238
    Published:6 Aug 2008
    7.8
    High

    CVE-2008-3494

    Last Modified: 11 Mar 2014

    8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading text placed before the real Host header.

    Source:nnposter
    Published:6 Aug 2008
    5
    Medium

    CVE-2008-3493

    Last Modified: 23 Apr 2026

    vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.

    Source:beford
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3491

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.

    Source:Mr.SQL
    Published:6 Aug 2008
    6.5
    Medium

    CVE-2008-3490

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to execute arbitrary SQL commands via the mail_id parameter in a veiw action.

    Source:Corwin
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3489

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie.

    Source:gnix
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3487

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3486

    Last Modified: 21 Dec 2016

    Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.

    Source:EgiX
    Published:6 Aug 2008
    7.5
    High

    CVE-2008-3484

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action to index.php.

    Source:Mr.SQL
    Published:5 Aug 2008
    4.3
    Medium

    CVE-2008-3483

    Last Modified: 8 Mar 2014

    Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page.

    Source:Portcullis
    Published:5 Aug 2008
    7.5
    High

    CVE-2008-3481

    Last Modified: 21 Dec 2016

    themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Source:EgiX
    Published:5 Aug 2008
    9.3
    Critical

    CVE-2008-3480

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter.

    Source:Core Security
    Published:29 Aug 2008
    7.2
    High

    CVE-2008-3464

    Last Modified: 23 Apr 2026

    afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."

    Source:Ruben Santamarta
    Published:15 Oct 2008
    10
    Critical

    CVE-2008-3455

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter.

    Source:RoMaNcYxHaCkEr
    Published:4 Aug 2008
    7.5
    High

    CVE-2008-3454

    Last Modified: 17 Oct 2010

    JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1.

    Source:Stack
    Published:4 Aug 2008
    6.8
    Medium

    CVE-2008-3452

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the loc_id parameter in a list_events action to mod.php.

    Source:Jack
    Published:4 Aug 2008
    4.3
    Medium

    CVE-2008-3448

    Last Modified: 10 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.

    Source:Ghost Hacker
    Published:4 Aug 2008
    5
    Medium

    CVE-2008-3447

    Last Modified: 23 Apr 2026

    The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.

    Source:kokanin
    Published:4 Aug 2008
    6.8
    Medium

    CVE-2008-3446

    Last Modified: 21 Dec 2016

    Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:NoGe
    Published:4 Aug 2008
    7.5
    High

    CVE-2008-3445

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter.

    Source:CraCkEr
    Published:4 Aug 2008
    5
    Medium

    CVE-2008-3443

    Last Modified: 21 Dec 2016

    The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows remote attackers to cause a denial of service (infinite loop and crash) via multiple long requests to a Ruby socket, related to memory allocation failure, and as demonstrated against Webrick.

    Source:laurent gaffié
    Published:14 Aug 2008
    6.8
    Medium

    CVE-2008-3432

    Last Modified: 13 Mar 2014

    Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.

    Source:Brian Hirt
    Published:29 Jan 2005
    8.8
    High

    CVE-2008-3431

    Last Modified: 22 Apr 2026

    The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.

    Source:Core Security
    Published:5 Aug 2008
    9.3
    Critical

    CVE-2008-3430

    Last Modified: 8 Mar 2014

    Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.

    Source:Edi Strosar
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3420

    Last Modified: 14 Dec 2016

    Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to browse.php or (2) the s parameter in an exhibitions action to detail.php.

    Source:dun
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3419

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.

    Source:Hussin X
    Published:31 Jul 2008