4.3
    Medium

    CVE-2008-2911

    Last Modified: 6 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.

    Source:RoMaNcYxHaCkEr
    Published:30 Jun 2008
    9.3
    Critical

    CVE-2008-2910

    Last Modified: 23 Apr 2026

    Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting property value.

    Source:Nine:Situations:Group
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2909

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter.

    Source:anonymous
    Published:30 Jun 2008
    9.3
    Critical

    CVE-2008-2908

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2907

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.

    Source:CWH Underground
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2906

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.

    Source:Virangar Security
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2905

    Last Modified: 26 Apr 2011

    PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Metasploit
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2904

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:anonymous
    Published:30 Jun 2008
    6.8
    Medium

    CVE-2008-2903

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.

    Source:Mr.SQL
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2902

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.

    Source:t0pP8uZz
    Published:30 Jun 2008
    6.5
    Medium

    CVE-2008-2901

    Last Modified: 7 Dec 2016

    Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address parameter to addressbook.php, the (2) getnews parameter to familynews.php, and the (3) poll_id parameter to home.php in a results action.

    Source:CWH Underground
    Published:30 Jun 2008
    7.5
    High

    CVE-2008-2900

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:27 Jun 2008
    9.3
    Critical

    CVE-2008-2898

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:CraCkEr
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2897

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:CWH Underground
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2896

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:cOndemned
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2895

    Last Modified: 14 Dec 2016

    Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:SkyOut
    Published:27 Jun 2008
    9.3
    Critical

    CVE-2008-2894

    Last Modified: 27 Feb 2014

    Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

    Source:Tan Chew Keong
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2893

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.

    Source:Hussin X
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2892

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.

    Source:His0k4
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2891

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a category action.

    Source:TurkishWarriorr
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2890

    Last Modified: 9 Dec 2016

    Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.

    Source:t0pP8uZz
    Published:27 Jun 2008
    6.8
    Medium

    CVE-2008-2889

    Last Modified: 27 Feb 2014

    Directory traversal vulnerability in the FTP client in AceBIT WISE-FTP 4.1.0 and 5.5.8 allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.

    Source:Tan Chew Keong
    Published:27 Jun 2008
    10
    Critical

    CVE-2008-2888

    Last Modified: 9 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[application][app_root] parameter to (1) collection.class.php and (2) content_image.class.php in lib/obj/.

    Source:CraCkEr
    Published:27 Jun 2008
    6.8
    Medium

    CVE-2008-2887

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:cOndemned
    Published:27 Jun 2008
    9.3
    Critical

    CVE-2008-2886

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.

    Source:cyberlog
    Published:27 Jun 2008
    9.3
    Critical

    CVE-2008-2885

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CLASSES_ROOT parameter.

    Source:CraCkEr
    Published:27 Jun 2008
    9.3
    Critical

    CVE-2008-2884

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: some of these details are obtained from third party information.

    Source:Ghost Hacker
    Published:27 Jun 2008
    7.5
    High

    CVE-2008-2883

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter. NOTE: some of these details are obtained from third party information.

    Source:cyberlog
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2882

    Last Modified: 8 Dec 2016

    upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a direct request.

    Source:KnocKout
    Published:26 Jun 2008
    5
    Medium

    CVE-2008-2881

    Last Modified: 9 Dec 2016

    Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Source:K-159
    Published:26 Jun 2008
    6.4
    Medium

    CVE-2008-2878

    Last Modified: 8 Dec 2016

    Open redirect vulnerability in rss_getfile.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the file parameter.

    Source:BugReport.IR
    Published:26 Jun 2008
    6.8
    Medium

    CVE-2008-2877

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter.

    Source:CraCkEr
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2876

    Last Modified: 9 Dec 2016

    Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the zone parameter.

    Source:StAkeR
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2875

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL commands via the hal parameter.

    Source:CWH Underground
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2874

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbjoke_id parameter, a different vector than CVE-2008-1050.

    Source:Hussin X
    Published:26 Jun 2008
    5
    Medium

    CVE-2008-2873

    Last Modified: 8 Dec 2016

    sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request to Db/urun.mdb.

    Source:KnocKout
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2872

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sayfa parameter.

    Source:KnocKout
    Published:26 Jun 2008
    4.3
    Medium

    CVE-2008-2871

    Last Modified: 27 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CraCkEr
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2870

    Last Modified: 9 Dec 2016

    Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via the (1) eventID parameter to event_info.php and the (2) userID parameter to list_user.php.

    Source:CWH Underground
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2869

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Source:Hussin X
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2868

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the iEve parameter.

    Source:Bl@ckbe@rD
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2867

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.

    Source:Hussin X
    Published:26 Jun 2008
    7.5
    High

    CVE-2008-2866

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to execute arbitrary SQL commands via the saArticle[ID] parameter.

    Source:anonymous
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2865

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbitrary SQL commands via the articleid parameter in a show_article action.

    Source:Mr.SQL
    Published:25 Jun 2008
    5
    Medium

    CVE-2008-2864

    Last Modified: 23 Apr 2026

    eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) trigger.asp or (2) common2.asp in cms/include/, which reveals the database path.

    Source:BugReport.IR
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2863

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.

    Source:BugReport.IR
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2862

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to ansFAQ.asp and the (2) template_id parameter to preview.asp.

    Source:BugReport.IR
    Published:25 Jun 2008
    4.3
    Medium

    CVE-2008-2861

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp.

    Source:BugReport.IR
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2860

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Source:Hussin X
    Published:25 Jun 2008
    5
    Medium

    CVE-2008-2859

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."

    Source:Travis Warren
    Published:25 Jun 2008