10
    Critical

    CVE-2008-3242

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code via a long argument to the StartUrl method. NOTE: some of these details are obtained from third party information.

    Source:Guido Landi
    Published:21 Jul 2008
    7.5
    High

    CVE-2008-3241

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:DNX
    Published:21 Jul 2008
    7.5
    High

    CVE-2008-3240

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in index.php in AlstraSoft Affiliate Network Pro allows remote attackers to execute arbitrary SQL commands via the pgm parameter in a directory action.

    Source:Hussin X
    Published:21 Jul 2008
    9.3
    Critical

    CVE-2008-3239

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers to upload and execute arbitrary code via a filename in the CONF[CRON_LOGFILE] parameter and file contents in the CONF[LOCALE_LONG_DATE_TIME] parameter.

    Source:Inphex
    Published:21 Jul 2008
    7.5
    High

    CVE-2008-3238

    Last Modified: 9 Nov 2016

    Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands via (1) the seller_id parameter in sellers_othersitem.php, (2) the productid parameter in classifieds.php, and (3) the id parameter in shop.php.

    Source:Encrypt3d.M!nd
    Published:21 Jul 2008
    4.3
    Medium

    CVE-2008-3237

    Last Modified: 9 Nov 2016

    Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to inject arbitrary web script or HTML via the productid parameter.

    Source:Encrypt3d.M!nd
    Published:21 Jul 2008
    6.5
    Medium

    CVE-2008-3234

    Last Modified: 23 Apr 2026

    sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.

    Source:eliteboy
    Published:18 Jul 2008
    4.3
    Medium

    CVE-2008-3233

    Last Modified: 4 May 2017

    Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:anonymous
    Published:18 Jul 2008
    7.5
    High

    CVE-2008-3213

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.php in a tablon action. NOTE: some of these details are obtained from third party information.

    Source:Mr.SQL
    Published:18 Jul 2008
    7.5
    High

    CVE-2008-3212

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:RMx
    Published:18 Jul 2008
    7.5
    High

    CVE-2008-3211

    Last Modified: 23 Apr 2026

    Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.

    Source:RMx
    Published:18 Jul 2008
    5
    Medium

    CVE-2008-3210

    Last Modified: 14 Dec 2016

    rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with a long domain name in a request URI, which triggers an assert error.

    Source:Mu Security
    Published:18 Jul 2008
    9.3
    Critical

    CVE-2008-3209

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control ActiveX control in biimgfrm.ocx. NOTE: some of these details are obtained from third party information.

    Source:r0ut3r
    Published:18 Jul 2008
    5
    Medium

    CVE-2008-3208

    Last Modified: 23 Apr 2026

    Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packets.

    Source:Exodus
    Published:18 Jul 2008
    9.3
    Critical

    CVE-2008-3207

    Last Modified: 14 Dec 2016

    PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) sourceFolder or (2) moduleFolder parameter.

    Source:N3TR00T3R
    Published:18 Jul 2008
    7.5
    High

    CVE-2008-3206

    Last Modified: 5 Mar 2014

    SQL injection vulnerability in browse.groups.php in Yuhhu Pubs Black Cat allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:RMx
    Published:18 Jul 2008
    5
    Medium

    CVE-2008-3205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.

    Source:StAkeR
    Published:17 Jul 2008
    7.5
    High

    CVE-2008-3204

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.

    Source:Hussin X
    Published:17 Jul 2008
    7.5
    High

    CVE-2008-3203

    Last Modified: 26 Oct 2016

    js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.

    Source:k1tk4t
    Published:17 Jul 2008
    4.3
    Medium

    CVE-2008-3202

    Last Modified: 3 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in Xomol CMS 1.2 allows remote attackers to inject arbitrary web script or HTML via the current_url parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Julian Rodriguez
    Published:17 Jul 2008
    4.3
    Medium

    CVE-2008-3201

    Last Modified: 3 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Pagefusion 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) acct_fname and (2) acct_lname parameters in an edit action, and the (3) PID, (4) PGID, and (5) rez parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Julian Rodriguez
    Published:17 Jul 2008
    7.5
    High

    CVE-2008-3200

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action.

    Source:CWH Underground
    Published:17 Jul 2008
    6.8
    Medium

    CVE-2008-3195

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors.

    Source:Th1nk3r
    Published:17 Sept 2008
    6.8
    Medium

    CVE-2008-3194

    Last Modified: 13 Dec 2016

    Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) langpref, (2) file, (3) blogpost, or (4) cat parameter.

    Source:BugReport.IR
    Published:16 Jul 2008
    7.5
    High

    CVE-2008-3193

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page parameter to the default URI.

    Source:S.W.A.T.
    Published:16 Jul 2008
    6.8
    Medium

    CVE-2008-3192

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in index.php in jSite 1.0 OE allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Source:S.W.A.T.
    Published:16 Jul 2008
    6.8
    Medium

    CVE-2008-3191

    Last Modified: 14 Dec 2016

    Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.

    Source:CWH Underground
    Published:16 Jul 2008
    6.8
    Medium

    CVE-2008-3190

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:cOndemned
    Published:16 Jul 2008
    7.5
    High

    CVE-2008-3189

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:16 Jul 2008
    4.3
    Medium

    CVE-2008-3186

    Last Modified: 24 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:sl4xUz
    Published:15 Jul 2008
    6.8
    Medium

    CVE-2008-3185

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.

    Source:K-159
    Published:15 Jul 2008
    4.3
    Medium

    CVE-2008-3184

    Last Modified: 3 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.

    Source:Jessica Hope
    Published:15 Jul 2008
    7.5
    High

    CVE-2008-3183

    Last Modified: 13 Dec 2016

    PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dirDepth parameter.

    Source:Ghost Hacker
    Published:15 Jul 2008
    9.3
    Critical

    CVE-2008-3182

    Last Modified: 14 Dec 2016

    Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL.

    Source:Shinnok
    Published:15 Jul 2008
    6.5
    Medium

    CVE-2008-3181

    Last Modified: 14 Dec 2016

    Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.

    Source:CWH Underground
    Published:15 Jul 2008
    4.3
    Medium

    CVE-2008-3180

    Last Modified: 14 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) pageid parameter or (2) PATH_INFO.

    Source:CWH Underground
    Published:15 Jul 2008
    7.5
    High

    CVE-2008-3179

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:S.W.A.T.
    Published:15 Jul 2008
    7.5
    High

    CVE-2008-3178

    Last Modified: 14 Dec 2016

    Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg content type, then accessing it via a direct request to the file in upload/.

    Source:CWH Underground
    Published:15 Jul 2008
    9.3
    Critical

    CVE-2008-3167

    Last Modified: 14 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin.

    Source:RoMaNcYxHaCkEr
    Published:14 Jul 2008
    9.3
    Critical

    CVE-2008-3166

    Last Modified: 14 Dec 2016

    PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sIncPath parameter.

    Source:RoMaNcYxHaCkEr
    Published:14 Jul 2008
    6.8
    Medium

    CVE-2008-3165

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

    Source:Ams
    Published:14 Jul 2008
    7.6
    High

    CVE-2008-3164

    Last Modified: 3 Mar 2014

    Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.

    Source:Cod3rZ
    Published:14 Jul 2008
    6.8
    Medium

    CVE-2008-3163

    Last Modified: 2 Mar 2014

    Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dodosmail_header_file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ahmadbady
    Published:14 Jul 2008
    9.3
    Critical

    CVE-2008-3162

    Last Modified: 3 Mar 2014

    Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.

    Source:astrange
    Published:14 Jul 2008
    4.3
    Medium

    CVE-2008-3161

    Last Modified: 4 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent, or (6) Cookie HTTP header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Deniz Cevik
    Published:14 Jul 2008
    6.9
    Medium

    CVE-2008-3158

    Last Modified: 13 Jul 2017

    Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.

    Source:Metasploit
    Published:11 Jul 2008
    9.3
    Critical

    CVE-2008-3156

    Last Modified: 23 Apr 2026

    The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.

    Source:Karol Wiesek
    Published:11 Jul 2008
    9.3
    Critical

    CVE-2008-3155

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method.

    Source:Karol Wiesek
    Published:11 Jul 2008
    7.5
    High

    CVE-2008-3154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:Bl@ckbe@rD
    Published:11 Jul 2008
    7.5
    High

    CVE-2008-3153

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

    Source:girex
    Published:11 Jul 2008