7.5
    High

    CVE-2008-2989

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via the go parameter.

    Source:SxCx
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2987

    Last Modified: 27 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_edit_submenu.php, (2) admin_new_submenu.php, and (3) admin_edit_topmenu.php in admin/.

    Source:CWH Underground
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2986

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the ourlinux_root_path parameter to (1) adodb-errorpear.inc.php and (2) adodb-pear.inc.php in adodb/.

    Source:CraCkEr
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2985

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter.

    Source:CraCkEr
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2984

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers to inject arbitrary web script or HTML via the lang[be_red_text] parameter.

    Source:CraCkEr
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2983

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2982

    Last Modified: 9 Dec 2016

    Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.

    Source:CraCkEr
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2981

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the thumb_template parameter.

    Source:CraCkEr
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2980

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.

    Source:CraCkEr
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2979

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in phpi/login.php in Ourvideo CMS 9.5 allow remote attackers to inject arbitrary web script or HTML via the (1) top_page and (2) end_page parameters.

    Source:CraCkEr
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2978

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the prefix parameter.

    Source:CraCkEr
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2977

    Last Modified: 9 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_connection parameter to (1) edit_top_feature.php and (2) edit_topics_feature.php in phpi/.

    Source:CraCkEr
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2976

    Last Modified: 9 Dec 2016

    Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) language parameter to (a) include_me.php, (b) admin/ajax.php, and (c) admin/objects/catalog.ajaxhandler.php; and the (2) prefix parameter to (d) admin/inc/config.php.

    Source:CraCkEr
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2975

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Source:CraCkEr
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2974

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter.

    Source:CraCkEr
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2973

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters.

    Source:CraCkEr
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2972

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in KbLance allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a comment action.

    Source:S.L TEAM
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2971

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in links-extern.php in CiBlog 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mr.SQL
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2970

    Last Modified: 8 Dec 2016

    Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.

    Source:BugReport.IR
    Published:2 Jul 2008
    5
    Medium

    CVE-2008-2969

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the dfile parameter.

    Source:BugReport.IR
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2968

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in rating.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the book_id parameter.

    Source:BugReport.IR
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2967

    Last Modified: 8 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to login.php and the (2) glb_sid parameter to hta/htmlarea.js.php, and allow remote authenticated users to inject arbitrary web script or HTML via an unspecified field in room.php.

    Source:BugReport.IR
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2966

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the user parameter. party information.

    Source:CWH Underground
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2965

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in viewforum.php in JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter.

    Source:CWH Underground
    Published:2 Jul 2008
    7.5
    High

    CVE-2008-2964

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in guide.php in ResearchGuide 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:dun
    Published:2 Jul 2008
    6.8
    Medium

    CVE-2008-2963

    Last Modified: 9 Dec 2016

    Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php.

    Source:CWH Underground
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2962

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php.

    Source:CWH Underground
    Published:2 Jul 2008
    5
    Medium

    CVE-2008-2961

    Last Modified: 9 Dec 2016

    Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) path and (2) p parameter.

    Source:CWH Underground
    Published:2 Jul 2008
    9.3
    Critical

    CVE-2008-2959

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.

    Source:shinnai
    Published:2 Jul 2008
    4.3
    Medium

    CVE-2008-2955

    Last Modified: 8 Apr 2014

    Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.

    Source:Juan Pablo Lopez Yacubian
    Published:28 Jun 2008
    5
    Medium

    CVE-2008-2952

    Last Modified: 1 Mar 2014

    liblber/io.c in OpenLDAP 2.2.4 to 2.4.10 allows remote attackers to cause a denial of service (program termination) via crafted ASN.1 BER datagrams that trigger an assertion error.

    Source:Cameron Hotchkies
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2950

    Last Modified: 14 Dec 2016

    The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.

    Source:Felipe Andres Manzano
    Published:7 Jul 2008
    6.8
    Medium

    CVE-2008-2949

    Last Modified: 1 Mar 2014

    Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

    Source:Eduardo Vela
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2948

    Last Modified: 1 Mar 2014

    Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

    Source:Eduardo Vela
    Published:30 Jun 2008
    6
    Medium

    CVE-2008-2943

    Last Modified: 1 Mar 2014

    Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulnerability," although there are likely scenarios in which a user is allowed to make administrative LDAP requests but does not have the privileges to stop the server.

    Source:anonymous
    Published:30 Jun 2008
    4.3
    Medium

    CVE-2008-2938

    Last Modified: 18 Jan 2018

    Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.

    Source:Simon Ryeo
    Published:11 Aug 2008
    6.2
    Medium

    CVE-2008-2936

    Last Modified: 23 Apr 2026

    Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.

    Source:RoMaNSoFt
    Published:14 Aug 2008
    7.5
    High

    CVE-2008-2935

    Last Modified: 12 Mar 2014

    Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

    Source:Chris Evans
    Published:31 Jul 2008
    7.1
    High

    CVE-2008-2930

    Last Modified: 17 Mar 2014

    Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.

    Source:Ulf Weltman
    Published:27 Aug 2008
    7.5
    High

    CVE-2008-2922

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long IRC message.

    Source:t0pP8uZz
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2921

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:t0pP8uZz
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2920

    Last Modified: 6 Dec 2016

    admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.

    Source:t0pP8uZz
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2919

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the sort parameter.

    Source:anonymous
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2918

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.

    Source:anonymous
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2917

    Last Modified: 4 Oct 2016

    SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Source:JosS
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2916

    Last Modified: 6 Dec 2016

    Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to showcategory.php and the (2) id parameter to software-description.php.

    Source:K-159
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2915

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execute arbitrary SQL commands via the (1) position or (2) kw parameter.

    Source:JosS
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2914

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information.

    Source:JosS
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2913

    Last Modified: 7 Dec 2016

    Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.

    Source:CWH Underground
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2912

    Last Modified: 6 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_search.php; the (2) cfg[path][contenido] parameter to (b) move_articles.php, (c) move_old_stats.php, (d) optimize_database.php, (e) run_newsletter_job.php, (f) send_reminder.php, (g) session_cleanup.php, and (h) setfrontenduserstate.php in contenido/cronjobs/, and (i) includes/include.newsletter_jobs_subnav.php and (j) plugins/content_allocation/includes/include.right_top.php in contenido/; the (3) cfg[path][templates] parameter to (k) includes/include.newsletter_jobs_subnav.php and (l) plugins/content_allocation/includes/include.right_top.php in contenido/; and the (4) cfg[templates][right_top_blank] parameter to (m) plugins/content_allocation/includes/include.right_top.php and (n) contenido/includes/include.newsletter_jobs_subnav.php in contenido/, different vectors than CVE-2006-5380.

    Source:RoMaNcYxHaCkEr
    Published:30 Jun 2008