7.5
    High

    CVE-2008-2504

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to netbutik.php and the (2) id parameter to product.php.

    Source:Mr.SQL
    Published:29 May 2008
    7.5
    High

    CVE-2008-2501

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) album parameter to thumbnails.php and the (2) pid parameter to displayimage.php.

    Source:cOndemned
    Published:29 May 2008
    7.5
    High

    CVE-2008-2499

    Last Modified: 22 Feb 2014

    Stack-based buffer overflow in the Community Services Multiplexer (aka MUX or StMux.exe) in IBM Lotus Sametime 7.5.1 CF1 and earlier, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code via a crafted URL.

    Source:Manuel Santamarina Suarez
    Published:29 May 2008
    4.3
    Medium

    CVE-2008-2496

    Last Modified: 30 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) login.php, and (3) credits.php in admin/, and (4) upgrade/index.php.

    Source:DSecRG
    Published:28 May 2008
    4.3
    Medium

    CVE-2008-2493

    Last Modified: 23 Feb 2014

    Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus Bulletin Board 3.4 allows remote attackers to inject arbitrary web script or HTML via the review parameter.

    Source:Unohope
    Published:28 May 2008
    7.5
    High

    CVE-2008-2492

    Last Modified: 23 Feb 2014

    Multiple SQL injection vulnerabilities in Campus Bulletin Board 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to post3/view.asp and the (2) review parameter to post3/book.asp.

    Source:Unohope
    Published:28 May 2008
    7.5
    High

    CVE-2008-2491

    Last Modified: 23 Feb 2014

    SQL injection vulnerability in adv_cat.php in AbleSpace 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:Jasbi
    Published:28 May 2008
    6.5
    Medium

    CVE-2008-2488

    Last Modified: 23 Apr 2026

    admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts.

    Source:Stack
    Published:28 May 2008
    7.5
    High

    CVE-2008-2487

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a webboard action.

    Source:Tesz
    Published:28 May 2008
    6.8
    Medium

    CVE-2008-2484

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Source:DNX
    Published:28 May 2008
    6.8
    Medium

    CVE-2008-2483

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Xomol CMS 1.20071213 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the op parameter.

    Source:DNX
    Published:28 May 2008
    7.5
    High

    CVE-2008-2482

    Last Modified: 28 Nov 2016

    Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load parameter in a go action.

    Source:DSecRG
    Published:28 May 2008
    10
    Critical

    CVE-2008-2481

    Last Modified: 30 Nov 2016

    PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.

    Source:Kacak
    Published:28 May 2008
    10
    Critical

    CVE-2008-2480

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the _pages_dir parameter.

    Source:DR.TOXIC
    Published:28 May 2008
    6.8
    Medium

    CVE-2008-2479

    Last Modified: 23 Feb 2014

    Multiple SQL injection vulnerabilities in phpFix 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) kind parameter to fix/browse.php and the (2) account parameter to auth/00_pass.php.

    Source:Unohope
    Published:28 May 2008
    8.5
    High

    CVE-2008-2478

    Last Modified: 21 Feb 2014

    scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this, stating "I'm unable to reproduce such an issue on multiple servers running different versions of cPanel.

    Source:Ali Jasbi
    Published:28 May 2008
    7.5
    High

    CVE-2008-2477

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:cOndemned
    Published:28 May 2008
    10
    Critical

    CVE-2008-2469

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.

    Source:Dan Kaminsky
    Published:23 Oct 2008
    6.8
    Medium

    CVE-2008-2463

    Last Modified: 22 Nov 2017

    The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Source:callAX
    Published:7 Jul 2008
    7.5
    High

    CVE-2008-2461

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in index.php in Netious CMS 0.4 allows remote attackers to execute arbitrary SQL commands via the pageid parameter, a different vector than CVE-2006-4047.

    Source:InjEctOr5
    Published:27 May 2008
    6.8
    Medium

    CVE-2008-2459

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Source:Stack
    Published:27 May 2008
    4.3
    Medium

    CVE-2008-2458

    Last Modified: 21 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.

    Source:CWH Underground
    Published:27 May 2008
    7.5
    High

    CVE-2008-2457

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:InjEctOr5
    Published:27 May 2008
    7.5
    High

    CVE-2008-2456

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter.

    Source:Niiub
    Published:27 May 2008
    7.5
    High

    CVE-2008-2455

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the rid parameter.

    Source:Saime
    Published:27 May 2008
    7.5
    High

    CVE-2008-2454

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the movie parameter to index.php.

    Source:Houssamix
    Published:27 May 2008
    7.5
    High

    CVE-2008-2453

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php.

    Source:InjEctOr5
    Published:27 May 2008
    4.3
    Medium

    CVE-2008-2449

    Last Modified: 20 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Isaac McGowan phpInstantGallery 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gallery parameter to (a) index.php and (b) image.php, and the (2) imgnum parameter to image.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:27 May 2008
    7.5
    High

    CVE-2008-2448

    Last Modified: 2 Dec 2016

    Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.

    Source:U238
    Published:27 May 2008
    7.5
    High

    CVE-2008-2447

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:Cr@zy_King
    Published:27 May 2008
    7.5
    High

    CVE-2008-2446

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) userid parameter to (a) profile.php in a "show moreinfo" action; the (2) bildid parameter to (b) picturegallery.php in a shownext action; the (3) id parameter to (c) filebase.php in a freigeben action, (d) schedule.php in a del action, and (e) profile.php in an observe action; and the (4) pmid parameter in a delete action and (5) folderid parameter in a showfolder action to (f) message.php.

    Source:myvx
    Published:27 May 2008
    4.3
    Medium

    CVE-2008-2445

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a show action.

    Source:myvx
    Published:27 May 2008
    7.5
    High

    CVE-2008-2444

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL commands via the langsel parameter.

    Source:His0k4
    Published:27 May 2008
    7.5
    High

    CVE-2008-2443

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter.

    Source:HaCkeR_EgY
    Published:27 May 2008
    9.3
    Critical

    CVE-2008-2427

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.

    Source:Shinnok
    Published:24 Jun 2008
    7.5
    High

    CVE-2008-2425

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:His0k4
    Published:23 May 2008
    7.5
    High

    CVE-2008-2422

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in index.php in Web Slider 0.6 allows remote attackers to execute arbitrary SQL commands via the slide parameter in a slides action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:fahn zichler
    Published:23 May 2008
    4.3
    Medium

    CVE-2008-2421

    Last Modified: 22 Feb 2014

    Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.

    Source:DSecRG
    Published:23 May 2008
    4.3
    Medium

    CVE-2008-2419

    Last Modified: 22 Feb 2014

    Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.

    Source:0x000000
    Published:21 May 2008
    7.5
    High

    CVE-2008-2417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary SQL commands via the qNo parameter.

    Source:CWH Underground
    Published:22 May 2008
    7.5
    High

    CVE-2008-2416

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the category parameter in a Fiction action, possibly related to sources/fiction.class.php.

    Source:His0k4
    Published:22 May 2008
    6.8
    Medium

    CVE-2008-2415

    Last Modified: 21 Feb 2014

    Directory traversal vulnerability in template/purpletech/base_include.php in DigitalHive (aka hive) 2.0 RC2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:ZoRLu
    Published:22 May 2008
    4.3
    Medium

    CVE-2008-2414

    Last Modified: 21 Feb 2014

    Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.

    Source:ZoRLu
    Published:22 May 2008
    4.3
    Medium

    CVE-2008-2413

    Last Modified: 21 Feb 2014

    Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:ZoRLu
    Published:22 May 2008
    7.5
    High

    CVE-2008-2412

    Last Modified: 21 Feb 2014

    SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ZoRLu
    Published:22 May 2008
    6.8
    Medium

    CVE-2008-2411

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in index.php in SazCart 1.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a details action.

    Source:JosS
    Published:22 May 2008
    4.3
    Medium

    CVE-2008-2398

    Last Modified: 21 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.

    Source:CWH Underground
    Published:21 May 2008
    7.5
    High

    CVE-2008-2396

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in an arbitrary element of the PAGES array parameter.

    Source:Raz0r
    Published:21 May 2008
    7.5
    High

    CVE-2008-2395

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in thread.php in AlkalinePHP 0.80.00 beta and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Stack
    Published:21 May 2008
    7.5
    High

    CVE-2008-2394

    Last Modified: 30 Nov 2016

    Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to contact.php and the (2) nid parameter to news.php.

    Source:dun
    Published:21 May 2008