7.5
    High

    CVE-2008-3418

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:dun
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3417

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.

    Source:U238
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3416

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.

    Source:girex
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3415

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bit parameter, as demonstrated by an upload to avatar/ of a .jpg file containing PHP sequences.

    Source:Khashayar Fereidani
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3414

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in line2.php in SiteAdmin allows remote attackers to execute arbitrary SQL commands via the art parameter.

    Source:Cr@zy_King
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3413

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Source:Hussin X
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3412

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.

    Source:mikeX
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3409

    Last Modified: 9 Mar 2014

    Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c.

    Source:Luigi Auriemma
    Published:31 Jul 2008
    6.8
    Medium

    CVE-2008-3408

    Last Modified: 14 Dec 2016

    Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a crafted m3u file.

    Source:Guido Landi
    Published:31 Jul 2008
    5
    Medium

    CVE-2008-3407

    Last Modified: 23 Apr 2026

    phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.

    Source:Encrypt3d.M!nd
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3406

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Encrypt3d.M!nd
    Published:31 Jul 2008
    6.8
    Medium

    CVE-2008-3405

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in index.php in Ricardo Amaral nzFotolog 0.4.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action_file parameter.

    Source:Khashayar Fereidani
    Published:31 Jul 2008
    4.3
    Medium

    CVE-2008-3404

    Last Modified: 8 Mar 2014

    Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the link parameter.

    Source:DSecRG
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3403

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Mr.SQL
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3402

    Last Modified: 21 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php.

    Source:Ghost Hacker
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3401

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.

    Source:Ghost Hacker
    Published:31 Jul 2008
    4.3
    Medium

    CVE-2008-3400

    Last Modified: 21 Dec 2016

    XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function.

    Source:AzzCoder
    Published:31 Jul 2008
    6.8
    Medium

    CVE-2008-3399

    Last Modified: 21 Dec 2016

    PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter.

    Source:AzzCoder
    Published:31 Jul 2008
    2.6
    Low

    CVE-2008-3398

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129.

    Source:AzzCoder
    Published:31 Jul 2008
    5
    Medium

    CVE-2008-3396

    Last Modified: 9 Mar 2014

    Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.

    Source:Luigi Auriemma
    Published:31 Jul 2008
    4.3
    Medium

    CVE-2008-3391

    Last Modified: 8 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.

    Source:CSDT
    Published:31 Jul 2008
    6.8
    Medium

    CVE-2008-3390

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:DSecRG
    Published:31 Jul 2008
    7.5
    High

    CVE-2008-3388

    Last Modified: 6 Mar 2014

    Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php.

    Source:CWH Underground
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3387

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.

    Source:Mr.SQL
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3386

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the UID parameter, a different vector than CVE-2007-4086.

    Source:Hussin X
    Published:30 Jul 2008
    6.8
    Medium

    CVE-2008-3385

    Last Modified: 21 Dec 2016

    Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:BeyazKurt
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3384

    Last Modified: 2 Dec 2016

    Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) module and (2) file parameters.

    Source:DSecRG
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3383

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.

    Source:Mr.SQL
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3382

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.

    Source:Mr.SQL
    Published:30 Jul 2008
    4.3
    Medium

    CVE-2008-3380

    Last Modified: 6 Mar 2014

    Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.

    Source:Dr.Crash
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3378

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Source:Mr.SQL
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3377

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.

    Source:cOndemned
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3375

    Last Modified: 5 Jan 2018

    The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.

    Source:GulfTech Security
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3374

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.

    Source:GulfTech Security
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3372

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.

    Source:Hussin X
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3371

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

    Source:NoGe
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3370

    Last Modified: 7 Mar 2014

    SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote attackers to execute arbitrary SQL commands via the user (user name) field.

    Source:Lars Heidelberg
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3369

    Last Modified: 5 Jan 2018

    SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:GulfTech Security
    Published:30 Jul 2008
    6.5
    Medium

    CVE-2008-3368

    Last Modified: 24 Oct 2016

    PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.

    Source:Khashayar Fereidani
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3366

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.

    Source:Hussin X
    Published:30 Jul 2008
    6.8
    Medium

    CVE-2008-3365

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language_full parameter.

    Source:DSecRG
    Published:30 Jul 2008
    9.3
    Critical

    CVE-2008-3364

    Last Modified: 23 Apr 2026

    Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.5 and 3.6; and Worry-Free Business Security (WFBS) 5.0 allows remote attackers to execute arbitrary code via a long string in the Server property, and possibly other properties. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3363

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the include parameter.

    Source:DSecRG
    Published:30 Jul 2008
    10
    Critical

    CVE-2008-3362

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.

    Source:SaO
    Published:30 Jul 2008
    7.5
    High

    CVE-2008-3361

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header.

    Source:Wojciech Pawlikowski
    Published:29 Jul 2008
    9.3
    Critical

    CVE-2008-3360

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability than CVE-2006-2494.

    Source:Guido Landi
    Published:29 Jul 2008
    7.5
    High

    CVE-2008-3355

    Last Modified: 26 Dec 2016

    SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.

    Source:nuclear
    Published:28 Jul 2008
    7.5
    High

    CVE-2008-3354

    Last Modified: 28 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bbPath[path] parameter to votepolls.php and the (2) bbPath[root_theme] parameter to config.php, different vectors than CVE-2006-0659. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ciph3r
    Published:28 Jul 2008
    7.5
    High

    CVE-2008-3352

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.

    Source:IRAQI
    Published:28 Jul 2008
    7.5
    High

    CVE-2008-3351

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action.

    Source:Mr.SQL
    Published:28 Jul 2008