6.8
    Medium

    CVE-2008-2858

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Virangar Security
    Published:25 Jun 2008
    5
    Medium

    CVE-2008-2857

    Last Modified: 23 Apr 2026

    AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Source:t0pP8uZz
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2856

    Last Modified: 18 Jan 2017

    SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:25 Jun 2008
    4.3
    Medium

    CVE-2008-2855

    Last Modified: 18 Jan 2017

    Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:CWH Underground
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2854

    Last Modified: 9 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Orlando CMS 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[preloc] parameter to (1) modules/core/logger/init.php and (2) AJAX/newscat.php.

    Source:Ciph3r
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2853

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.

    Source:Mr.SQL
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2847

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL commands via the categori parameter in a pocategorisell action to modules.php.

    Source:HaCkeR_EgY
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2846

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL commands via the type parameter.

    Source:Stack
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2845

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:HaCkeR_EgY
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2844

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Stack
    Published:25 Jun 2008
    7.5
    High

    CVE-2008-2843

    Last Modified: 8 Dec 2016

    Multiple SQL injection vulnerabilities in doITLive CMS 2.50 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter in an USUB action to default.asp and the (2) Licence[SpecialLicenseNumber] (aka LicenceId) cookie to edit/default.asp.

    Source:BugReport.IR
    Published:25 Jun 2008
    4.3
    Medium

    CVE-2008-2842

    Last Modified: 8 Dec 2016

    Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers to inject arbitrary web script or HTML via the FILE parameter.

    Source:BugReport.IR
    Published:25 Jun 2008
    6.8
    Medium

    CVE-2008-2841

    Last Modified: 7 Dec 2016

    Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.

    Source:securfrog
    Published:13 Jun 2008
    4.3
    Medium

    CVE-2008-2839

    Last Modified: 8 Dec 2016

    Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter to index.php.

    Source:CWH Underground
    Published:24 Jun 2008
    5
    Medium

    CVE-2008-2838

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

    Source:CWH Underground
    Published:24 Jun 2008
    7.5
    High

    CVE-2008-2837

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter.

    Source:dun
    Published:24 Jun 2008
    7.5
    High

    CVE-2008-2836

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the includedir parameter and a 0 value for the noSet parameter, a different vector than CVE-2007-1483.

    Source:Cr@zy_King
    Published:24 Jun 2008
    7.5
    High

    CVE-2008-2835

    Last Modified: 12 Dec 2018

    SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL commands via the formid parameter.

    Source:Guido Landi
    Published:24 Jun 2008
    7.5
    High

    CVE-2008-2834

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:24 Jun 2008
    10
    Critical

    CVE-2008-2833

    Last Modified: 23 Apr 2026

    admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in images/, via a nonzero value for the submit0 parameter in conjunction with filenames in the filename and upload parameters.

    Source:t0pP8uZz
    Published:24 Jun 2008
    10
    Critical

    CVE-2008-2832

    Last Modified: 8 Dec 2016

    Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.

    Source:Alemin_Krali
    Published:24 Jun 2008
    7.2
    High

    CVE-2008-2830

    Last Modified: 27 Feb 2014

    Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of scripting addition plugins, which allows local users to gain privileges via scripting addition commands to a privileged application, as originally demonstrated by an osascript tell command to ARDAgent.

    Source:anonymous
    Published:23 Jun 2008
    4.6
    Medium

    CVE-2008-2827

    Last Modified: 27 Feb 2014

    The rmtree function in lib/File/Path.pm in Perl 5.10 does not properly check permissions before performing a chmod, which allows local users to modify the permissions of arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448 and CVE-2004-0452.

    Source:Frans Pop
    Published:20 Jun 2008
    7.5
    High

    CVE-2008-2823

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.

    Source:t0pP8uZz
    Published:23 Jun 2008
    9.3
    Critical

    CVE-2008-2822

    Last Modified: 26 Feb 2014

    Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a (1) LIST or (2) MLSD command.

    Source:Tan Chew Keong
    Published:23 Jun 2008
    9.3
    Critical

    CVE-2008-2821

    Last Modified: 26 Feb 2014

    Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-2002-1345.

    Source:Tan Chew Keong
    Published:23 Jun 2008
    6.4
    Medium

    CVE-2008-2820

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:DSecRG
    Published:23 Jun 2008
    7.5
    High

    CVE-2008-2818

    Last Modified: 6 Dec 2016

    Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the section parameter to the default URI.

    Source:Loader007
    Published:23 Jun 2008
    7.5
    High

    CVE-2008-2817

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the CatId parameter in a show action.

    Source:Mr.SQL
    Published:23 Jun 2008
    7.5
    High

    CVE-2008-2816

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbitrary SQL commands via the repquote parameter in a reply action, a different vector than CVE-2006-1572.

    Source:anonymous
    Published:23 Jun 2008
    7.5
    High

    CVE-2008-2815

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:anonymous
    Published:23 Jun 2008
    4.3
    Medium

    CVE-2008-2814

    Last Modified: 6 Dec 2016

    Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:CWH Underground
    Published:23 Jun 2008
    6.8
    Medium

    CVE-2008-2813

    Last Modified: 6 Dec 2016

    Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:CWH Underground
    Published:23 Jun 2008
    7.5
    High

    CVE-2008-2796

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:Mr.SQL
    Published:20 Jun 2008
    4.3
    Medium

    CVE-2008-2795

    Last Modified: 27 Feb 2014

    Directory traversal vulnerability in the FTP and SFTP clients in IDM Computer Solutions Inc UltraEdit 14.00b allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) or a ..\ (dot dot backslash) in a response to a LIST command.

    Source:Tan Chew Keong
    Published:20 Jun 2008
    7.5
    High

    CVE-2008-2793

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Source:SuNHouSe2
    Published:20 Jun 2008
    7.5
    High

    CVE-2008-2792

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter.

    Source:Mr.SQL
    Published:20 Jun 2008
    7.5
    High

    CVE-2008-2791

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mr.SQL
    Published:20 Jun 2008
    7.5
    High

    CVE-2008-2790

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:anonymous
    Published:20 Jun 2008
    7.5
    High

    CVE-2008-2789

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Source:Mr.SQL
    Published:20 Jun 2008
    4.3
    Medium

    CVE-2008-2787

    Last Modified: 27 Feb 2014

    Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter.

    Source:Sergi Rosello
    Published:20 Jun 2008
    4.3
    Medium

    CVE-2008-2783

    Last Modified: 23 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde parameter in the PATH_INFO to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ivan Sanchez
    Published:19 Jun 2008
    7.5
    High

    CVE-2008-2782

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) library_rss.php and (2) rss.php.

    Source:Saime
    Published:19 Jun 2008
    7.5
    High

    CVE-2008-2781

    Last Modified: 23 Feb 2014

    SQL injection vulnerability in index.php in DZOIC Handshakes 3.5 allows remote attackers to execute arbitrary SQL commands via the fname parameter in a members search action.

    Source:Ali Jasbi
    Published:19 Jun 2008
    7.5
    High

    CVE-2008-2778

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:The:Paradox
    Published:19 Jun 2008
    7.5
    High

    CVE-2008-2774

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execute arbitrary SQL commands via the category_id parameter, a different vector than CVE-2007-4736.

    Source:Cr@zy_King
    Published:19 Jun 2008
    7.5
    High

    CVE-2008-2770

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.

    Source:CWH Underground
    Published:18 Jun 2008
    7.5
    High

    CVE-2008-2755

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:anonymous
    Published:18 Jun 2008
    6.8
    Medium

    CVE-2008-2754

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the list parameter.

    Source:Mr.SQL
    Published:18 Jun 2008
    7.5
    High

    CVE-2008-2753

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) xslIdn parameter to (a) utils/getXsl.aspx, and the (2) part parameter to (b) getXml.aspx and (c) getXls.aspx in utils/.

    Source:BugReport.IR
    Published:18 Jun 2008