7.5
    High

    CVE-2008-3152

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter.

    Source:Hamtaro
    Published:11 Jul 2008
    7.5
    High

    CVE-2008-3151

    Last Modified: 3 Mar 2014

    SQL injection vulnerability in the 4ndvddb 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a show_dvd action.

    Source:Lovebug
    Published:11 Jul 2008
    10
    Critical

    CVE-2008-3150

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access restrictions that were implemented in sess.php.

    Source:Ams
    Published:11 Jul 2008
    6.8
    Medium

    CVE-2008-3148

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary code via a crafted DLL file that contains a long string.

    Source:Defsanguje
    Published:11 Jul 2008
    5
    Medium

    CVE-2008-3140

    Last Modified: 3 Mar 2014

    The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors, possibly related to an "incomplete SS7 MSU syslog encapsulated packet."

    Source:Noam Rathus
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-3136

    Last Modified: 12 Dec 2016

    SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:n0c0py
    Published:10 Jul 2008
    6.8
    Medium

    CVE-2008-3133

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Source:CWH Underground
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3132

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pet parameter to index.php.

    Source:His0k4
    Published:10 Jul 2008
    6.8
    Medium

    CVE-2008-3131

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showid parameter.

    Source:DNX
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3129

    Last Modified: 14 Dec 2016

    Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form.

    Source:anonymous
    Published:10 Jul 2008
    5
    Medium

    CVE-2008-3128

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.

    Source:Nine:Situations:Group
    Published:10 Jul 2008
    6.8
    Medium

    CVE-2008-3127

    Last Modified: 14 Dec 2016

    PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.

    Source:Ghost Hacker
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3125

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:t0pP8uZz
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3124

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL commands via the file parameter.

    Source:t0pP8uZz
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3123

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.

    Source:t0pP8uZz
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3119

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:Hussin X
    Published:10 Jul 2008
    7.5
    High

    CVE-2008-3118

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the vid parameter.

    Source:EgiX
    Published:10 Jul 2008
    6.5
    Medium

    CVE-2008-3117

    Last Modified: 9 Dec 2016

    Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/.

    Source:EgiX
    Published:10 Jul 2008
    10
    Critical

    CVE-2008-3116

    Last Modified: 28 Feb 2014

    Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.

    Source:superkhung
    Published:10 Jul 2008
    4.3
    Medium

    CVE-2008-3101

    Last Modified: 4 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.

    Source:Fabian Fingerle
    Published:3 Sept 2008
    4.3
    Medium

    CVE-2008-3100

    Last Modified: 8 Mar 2014

    Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php.

    Source:Fabian Fingerle
    Published:29 Jul 2008
    4.3
    Medium

    CVE-2008-3098

    Last Modified: 21 Mar 2014

    Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.

    Source:Fabian Fingerle
    Published:24 Sept 2008
    6.5
    Medium

    CVE-2008-3093

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and execute arbitrary PHP code by placing a .php filename in the Upload_Avatar parameter and sending the image/gif content type.

    Source:PHPLizardo
    Published:9 Jul 2008
    7.5
    High

    CVE-2008-3089

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute arbitrary SQL commands via the uid parameter.

    Source:HIva Team
    Published:9 Jul 2008
    4.3
    Medium

    CVE-2008-3088

    Last Modified: 13 Dec 2016

    Cross-site scripting (XSS) vulnerability in the Files module in Kasseler CMS 1.3.0 and 1.3.1 Lite allows remote attackers to inject arbitrary web script or HTML via the cid parameter in a Category action to index.php.

    Source:Cr@zy_King
    Published:9 Jul 2008
    5
    Medium

    CVE-2008-3087

    Last Modified: 13 Dec 2016

    Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to index.php, possibly related to the phpManual module.

    Source:Cr@zy_King
    Published:9 Jul 2008
    7.5
    High

    CVE-2008-3083

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:His0k4
    Published:9 Jul 2008
    5.1
    Medium

    CVE-2008-3080

    Last Modified: 14 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899.

    Source:Jesper Jurcenoks
    Published:9 Jul 2008
    9.3
    Critical

    CVE-2008-3076

    Last Modified: 3 Mar 2014

    The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

    Source:Jan Minar
    Published:15 Jul 2008
    7.5
    High

    CVE-2008-3058

    Last Modified: 2 Apr 2014

    Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL commands via the FormValue_Email parameter (aka Email field) to index.php in (1) member/, (2) client/, or (3) admin/; or (4) the FormValue_SearchKeywords parameter to client/campaign_track.php.

    Source:security curmudgeon
    Published:3 Dec 2008
    7.5
    High

    CVE-2008-3036

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in index.php in CMS little 0.0.1 allows remote attackers to include and execute arbitrary local files, and probably remote files, via a .. (dot dot) in the template parameter.

    Source:CWH Underground
    Published:7 Jul 2008
    6.5
    Medium

    CVE-2008-3035

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.

    Source:haZl0oh
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3034

    Last Modified: 9 Dec 2016

    Multiple SQL injection vulnerabilities in RSS-aggregator 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) IdFlux parameter to admin/fonctions/supprimer_flux.php and the (2) IdTag parameter to admin/fonctions/supprimer_tag.php.

    Source:CWH Underground
    Published:7 Jul 2008
    9.3
    Critical

    CVE-2008-3033

    Last Modified: 9 Dec 2016

    RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

    Source:CWH Underground
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3031

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:StAkeR
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3030

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an urunler action.

    Source:Kacak
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3027

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the article_ID parameter to index.php.

    Source:CWH Underground
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3026

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3025

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter in a redir action.

    Source:Hussin X
    Published:7 Jul 2008
    9.3
    Critical

    CVE-2008-3024

    Last Modified: 2 Mar 2014

    Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.

    Source:Filipe Balestra
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-3022

    Last Modified: 14 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remote attackers to execute arbitrary PHP code via a URL in (1) icerikyolu, (2) sayfaid, and (3) uzanti parameters.

    Source:Ciph3r
    Published:7 Jul 2008
    9.3
    Critical

    CVE-2008-3013

    Last Modified: 23 Apr 2026

    gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."

    Source:John Smith
    Published:10 Sept 2008
    9.3
    Critical

    CVE-2008-3008

    Last Modified: 28 Mar 2019

    Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability."

    Source:haluznik
    Published:10 Sept 2008
    4.3
    Medium

    CVE-2008-2997

    Last Modified: 7 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action.

    Source:CWH Underground
    Published:3 Jul 2008
    6.8
    Medium

    CVE-2008-2996

    Last Modified: 7 Dec 2016

    Multiple SQL injection vulnerabilities in index.php in Gravity Board X (GBX) 2.0 Beta, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchquery parameter in a getsearch action, and the (2) board_id parameter in a viewboard action.

    Source:brain[pillow]
    Published:3 Jul 2008
    7.5
    High

    CVE-2008-2995

    Last Modified: 26 Feb 2014

    Multiple SQL injection vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to execute arbitrary SQL commands via (1) the annuaire parameter to annuaire.php or (2) the username field in admin/login.php.

    Source:Sylvain THUAL
    Published:3 Jul 2008
    4.3
    Medium

    CVE-2008-2994

    Last Modified: 26 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PHPEasyData 1.5.4 allow remote attackers to inject arbitrary web script or HTML via the (1) annuaire parameter to (a) last_records.php and (b) annuaire.php and the (2) by and (3) cat_id parameters to annuaire.php.

    Source:Sylvain THUAL
    Published:3 Jul 2008
    7.5
    High

    CVE-2008-2993

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) fog_lang and (2) fog_skin parameters, probably related to libs/required/share.inc; and possibly the (3) fog_pseudo, (4) fog_posted, (5) fog_password, and (6) fog_cook parameters.

    Source:CWH Underground
    Published:3 Jul 2008
    7.8
    High

    CVE-2008-2992

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.

    Source:Metasploit
    Published:4 Nov 2008
    7.5
    High

    CVE-2008-2990

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compath parameter.

    Source:Kacak
    Published:2 Jul 2008