4.3
    Medium

    CVE-2008-2644

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1) data parameter to catalog.php, the (2) keyword parameter to search.php, the (3) page parameter to bb.php, and the (4) new_s parameter to order.php.

    Source:CWH Underground
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2643

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer action to index.php.

    Source:Stack
    Published:10 Jun 2008
    7.6
    High

    CVE-2008-2639

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.

    Source:Kevin Finisterre
    Published:16 Jun 2008
    10
    Critical

    CVE-2008-2638

    Last Modified: 5 Dec 2016

    Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.

    Source:JIKO
    Published:10 Jun 2008
    4.3
    Medium

    CVE-2008-2637

    Last Modified: 25 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.php and (2) the sql_matchscope parameter in vdesk/admincon/index.php.

    Source:nnposter
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2634

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.

    Source:KnocKout
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2633

    Last Modified: 5 Dec 2016

    Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.

    Source:His0k4
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2632

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subscribe action to index.php.

    Source:His0k4
    Published:10 Jun 2008
    5
    Medium

    CVE-2008-2631

    Last Modified: 5 Dec 2016

    The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted HTTP POST request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:securfrog
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2630

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php.

    Source:boom3rang
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2629

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.

    Source:DreamTurk
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:His0k4
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2627

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the userid parameter in a userblog action to index.php.

    Source:His0k4
    Published:10 Jun 2008
    7.5
    High

    CVE-2008-2626

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter.

    Source:Bl@ckbe@rD
    Published:10 Jun 2008
    5
    Medium

    CVE-2008-2595

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.

    Source:Joxean Koret
    Published:15 Jul 2008
    7.5
    High

    CVE-2008-2574

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in tus_imagenes/.

    Source:ilker Kandemir
    Published:6 Jun 2008
    8.5
    High

    CVE-2008-2573

    Last Modified: 3 Dec 2016

    Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) command.

    Source:securfrog
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2572

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL commands via the articulo_id parameter.

    Source:HER0
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2569

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php.

    Source:ZAMUT
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2568

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a browse action to index.php.

    Source:eXeCuTeR
    Published:6 Jun 2008
    4.3
    Medium

    CVE-2008-2566

    Last Modified: 18 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.

    Source:Stefan Schurtz
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2565

    Last Modified: 18 Dec 2016

    Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.

    Source:Stefan Schurtz
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2564

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

    Source:His0k4
    Published:6 Jun 2008
    6.5
    Medium

    CVE-2008-2562

    Last Modified: 5 Dec 2016

    SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.

    Source:MustLive
    Published:6 Jun 2008
    4.3
    Medium

    CVE-2008-2561

    Last Modified: 7 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2 parameters to register.php; the (5) email parameter to reminder.php; and the (6) keywords parameter to search.php.

    Source:CWH Underground
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2560

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.

    Source:CWH Underground
    Published:6 Jun 2008
    7.5
    High

    CVE-2008-2556

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action.

    Source:Lidloses_Auge
    Published:5 Jun 2008
    7.5
    High

    CVE-2008-2555

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Source:Lidloses_Auge
    Published:5 Jun 2008
    7.5
    High

    CVE-2008-2554

    Last Modified: 1 Dec 2016

    Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.

    Source:JosS
    Published:5 Jun 2008
    9.3
    Critical

    CVE-2008-2551

    Last Modified: 23 Apr 2026

    The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."

    Source:Nine:Situations:Group
    Published:4 Jun 2008
    4.3
    Medium

    CVE-2008-2549

    Last Modified: 11 Jul 2017

    Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed PDF document, as demonstrated by 2008-HI2.pdf.

    Source:securfrog
    Published:29 May 2008
    6.8
    Medium

    CVE-2008-2542

    Last Modified: 24 Feb 2014

    Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to execute arbitrary code via a crafted PNM file.

    Source:Alfredo Ortega
    Published:5 Jun 2008
    7.5
    High

    CVE-2008-2537

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cat.php in HispaH Model Search allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:InjEctOr5
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2536

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter.

    Source:Stack
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2535

    Last Modified: 2 Dec 2016

    Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbitrary SQL commands via the del parameter to (1) gbuch.admin.php, (2) links.admin.php, (3) menue.admin.php, (4) news.admin.php, and (5) todo.admin.php in admin/module/.

    Source:tw8
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2534

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ltarget parameter.

    Source:tw8
    Published:3 Jun 2008
    4.3
    Medium

    CVE-2008-2533

    Last Modified: 2 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ltarget parameter to (a) admin/admin_frame.php and the (2) conf parameter to (b) gbuch.admin.php, (c) links.admin.php, (d) menue.admin.php, (e) news.admin.php, and (f) todo.admin.php in admin/module/.

    Source:tw8
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2532

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:InjEctOr5
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2530

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter to (a) frontend/news.php, the (2) id parameter to (b) events3.php and (c) videos2.php in frontend/, the (3) y parameter to (d) frontend/events2.php, and the (4) ser parameter to (e) frontend/fotos2.php.

    Source:Lidloses_Auge
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2529

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbitrary SQL commands via the catId parameter.

    Source:His0k4
    Published:3 Jun 2008
    6.8
    Medium

    CVE-2008-2522

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action.

    Source:Stack
    Published:3 Jun 2008
    6.5
    Medium

    CVE-2008-2521

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.

    Source:TurkishWarriorr
    Published:3 Jun 2008
    7.5
    High

    CVE-2008-2520

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][addon] parameter to (a) addon/smarty/plugins/function.captcha.php and (b) system/classes/sql/AdoDBConnection.php; and the (2) GLOBALS[_BIGACE][DIR][admin] parameter to (c) item_information.php and (d) jstree.php in system/application/util/, and (e) system/admin/plugins/menu/menuTree/plugin.php, different vectors than CVE-2006-4423.

    Source:BiNgZa
    Published:3 Jun 2008
    9.3
    Critical

    CVE-2008-2511

    Last Modified: 1 Dec 2016

    Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: some of these details are obtained from third party information.

    Source:Nine:Situations:Group
    Published:2 Jun 2008
    7.5
    High

    CVE-2008-2510

    Last Modified: 23 Feb 2014

    SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter.

    Source:eserg.ru
    Published:29 May 2008
    7.5
    High

    CVE-2008-2509

    Last Modified: 23 Feb 2014

    SQL injection vulnerability in pwd.asp in Excuse Online allows remote attackers to execute arbitrary SQL commands via the pID parameter.

    Source:Unohope
    Published:29 May 2008
    4.3
    Medium

    CVE-2008-2508

    Last Modified: 24 Feb 2014

    Cross-site scripting (XSS) vulnerability in news.php in Tr Script News 2.1 allows remote attackers to inject arbitrary web script or HTML via the "nb" parameter in voir mode.

    Source:ZoRLu
    Published:29 May 2008
    4.3
    Medium

    CVE-2008-2507

    Last Modified: 24 Feb 2014

    Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the CalendarName parameter in a ShowIt action.

    Source:Marvin Simkin
    Published:29 May 2008
    7.5
    High

    CVE-2008-2506

    Last Modified: 30 Nov 2016

    Multiple SQL injection vulnerabilities in Simpel Side Weblosning 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) mainid and (2) id parameters to index2.php.

    Source:Mr.SQL
    Published:29 May 2008
    4.3
    Medium

    CVE-2008-2505

    Last Modified: 30 Nov 2016

    Cross-site scripting (XSS) vulnerability in result.php in Simpel Side Weblosning 1 through 4 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Mr.SQL
    Published:29 May 2008