7.5
    High

    CVE-2008-2393

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mr.SQL
    Published:21 May 2008
    6.8
    Medium

    CVE-2008-2390

    Last Modified: 23 Apr 2026

    Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument.

    Source:callAX
    Published:21 May 2008
    5
    Medium

    CVE-2008-2382

    Last Modified: 3 Apr 2014

    The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message.

    Source:Alfredo Ortega
    Published:22 Dec 2008
    5
    Medium

    CVE-2008-2370

    Last Modified: 10 Mar 2014

    Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

    Source:Stefano Di Paola
    Published:1 Aug 2008
    4.7
    Medium

    CVE-2008-2365

    Last Modified: 6 Sept 2016

    Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.

    Source:Alexei Dobryanov
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-2356

    Last Modified: 30 Nov 2016

    SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbitrary SQL commands via the post_id parameter.

    Source:Stack
    Published:20 May 2008
    6.8
    Medium

    CVE-2008-2355

    Last Modified: 30 Nov 2016

    Directory traversal vulnerability in index.php in WR-Meeting 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the msnum parameter in a coment event.

    Source:Cr@zy_King
    Published:20 May 2008
    7.5
    High

    CVE-2008-2353

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter.

    Source:t0pP8uZz
    Published:20 May 2008
    6.8
    Medium

    CVE-2008-2352

    Last Modified: 30 Nov 2016

    Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie.

    Source:0in
    Published:20 May 2008
    7.5
    High

    CVE-2008-2351

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQL commands via the (1) lang_id and (2) menu_id parameters.

    Source:dun
    Published:20 May 2008
    5
    Medium

    CVE-2008-2350

    Last Modified: 21 Feb 2014

    Directory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot) or (2) C: folder sequences in the file parameter.

    Source:Lostmon
    Published:20 May 2008
    7.5
    High

    CVE-2008-2349

    Last Modified: 23 Apr 2026

    Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.

    Source:ArxWolf
    Published:20 May 2008
    7.5
    High

    CVE-2008-2348

    Last Modified: 2 Dec 2016

    MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via a direct request to admin/adduser.php.

    Source:t0pP8uZz
    Published:20 May 2008
    7.5
    High

    CVE-2008-2347

    Last Modified: 23 Apr 2026

    MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admin" in a direct request to admin/addUser.php.

    Source:t0pP8uZz
    Published:20 May 2008
    7.5
    High

    CVE-2008-2346

    Last Modified: 30 Nov 2016

    AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a direct request to adduser.php.

    Source:t0pP8uZz
    Published:20 May 2008
    7.5
    High

    CVE-2008-2343

    Last Modified: 2 Dec 2016

    News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.

    Source:GoLd_M
    Published:19 May 2008
    5
    Medium

    CVE-2008-2342

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Source:GoLd_M
    Published:19 May 2008
    7.5
    High

    CVE-2008-2341

    Last Modified: 2 Dec 2016

    PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.

    Source:GoLd_M
    Published:19 May 2008
    7.5
    High

    CVE-2008-2340

    Last Modified: 2 Dec 2016

    Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.

    Source:GoLd_M
    Published:19 May 2008
    7.5
    High

    CVE-2008-2339

    Last Modified: 21 Feb 2014

    SQL injection vulnerability in index.php in Turnkey Web Tools SunShop Shopping Cart 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action, a different vector than CVE-2008-2038, CVE-2007-4597, and CVE-2007-2549.

    Source:irvian
    Published:19 May 2008
    7.5
    High

    CVE-2008-2338

    Last Modified: 23 Apr 2026

    Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin.

    Source:t0pP8uZz
    Published:19 May 2008
    7.5
    High

    CVE-2008-2337

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kategoria parameter to (a) galeria.php and the (2) id_phot parameter to (b) popup/koment.php and (c) popup/opis.php in, different vectors than CVE-2006-3163.

    Source:cOndemned
    Published:19 May 2008
    7.5
    High

    CVE-2008-2336

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:HaCkeR_EgY
    Published:19 May 2008
    4.3
    Medium

    CVE-2008-2335

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: some of these details are obtained from third party information. NOTE: it was later reported that 1.2.3 is also affected.

    Source:3spi0n
    Published:19 May 2008
    7.5
    High

    CVE-2008-2334

    Last Modified: 21 Feb 2014

    Multiple SQL injection vulnerabilities in W1L3D4 Philboard 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) forumid parameter to (a) admin/philboard_admin-forumedit.asp, (b) admin/philboard_admin-forum.asp, and (c) W1L3D4_foruma_yeni_konu_ac.asp; the (2) id parameter to (d) W1L3D4_konuoku.asp and (e) W1L3D4_konuya_mesaj_yaz.asp; and the (3) topic parameter to W1L3D4_konuya_mesaj_yaz.asp, different vectors than CVE-2008-1939, CVE-2007-2641, and CVE-2007-0920. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:U238
    Published:19 May 2008
    4.3
    Medium

    CVE-2008-2333

    Last Modified: 22 Feb 2014

    Cross-site scripting (XSS) vulnerability in ldap_test.cgi in Barracuda Spam Firewall (BSF) before 3.5.11.025 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Source:Information Risk Management Plc
    Published:23 May 2008
    5
    Medium

    CVE-2008-2326

    Last Modified: 19 Mar 2014

    mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer dereference and application crash) by resolving a crafted .local domain name that contains a long label.

    Source:Mario Ballano Bárcena
    Published:10 Sept 2008
    9.3
    Critical

    CVE-2008-2321

    Last Modified: 10 Mar 2014

    Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments."

    Source:Michal Zalewski
    Published:4 Aug 2008
    6.8
    Medium

    CVE-2008-2304

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string XML element that contains many characters.

    Source:Adriel T. Desautels
    Published:14 Jul 2008
    10
    Critical

    CVE-2008-2303

    Last Modified: 4 Mar 2014

    Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

    Source:Hiromitsu Takagi
    Published:14 Jul 2008
    7.5
    High

    CVE-2008-2301

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) top_view.php.

    Source:Virangar Security
    Published:18 May 2008
    7.5
    High

    CVE-2008-2298

    Last Modified: 2 Dec 2016

    Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.

    Source:t0pP8uZz
    Published:18 May 2008
    7.5
    High

    CVE-2008-2297

    Last Modified: 2 Dec 2016

    The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably passes an insufficient comparison.

    Source:t0pP8uZz
    Published:18 May 2008
    7.5
    High

    CVE-2008-2296

    Last Modified: 29 Nov 2016

    PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.

    Source:e.wiZz!
    Published:18 May 2008
    4.3
    Medium

    CVE-2008-2295

    Last Modified: 29 Nov 2016

    Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.

    Source:e.wiZz!
    Published:18 May 2008
    7.5
    High

    CVE-2008-2294

    Last Modified: 23 Apr 2026

    Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "admin."

    Source:t0pP8uZz
    Published:18 May 2008
    7.5
    High

    CVE-2008-2293

    Last Modified: 23 Apr 2026

    admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1.

    Source:t0pP8uZz
    Published:18 May 2008
    6.8
    Medium

    CVE-2008-2292

    Last Modified: 23 Apr 2026

    Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).

    Source:Praveen Darshanam
    Published:5 Nov 2007
    7.5
    High

    CVE-2008-2286

    Last Modified: 13 Nov 2013

    SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows remote attackers to execute arbitrary SQL commands via unspecified string fields in a notification packet.

    Source:Metasploit
    Published:18 May 2008
    7.5
    High

    CVE-2008-2284

    Last Modified: 20 Feb 2014

    PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBOX_APPLICATION_PATH parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:MajnOoNxHaCkEr
    Published:18 May 2008
    9.3
    Critical

    CVE-2008-2283

    Last Modified: 23 Apr 2026

    IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.

    Source:shinnai
    Published:18 May 2008
    7.5
    High

    CVE-2008-2282

    Last Modified: 23 Apr 2026

    admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.

    Source:t0pP8uZz
    Published:18 May 2008
    9.3
    Critical

    CVE-2008-2281

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.

    Source:Aviv Raff
    Published:18 May 2008
    5
    Medium

    CVE-2008-2279

    Last Modified: 29 Nov 2016

    Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table.

    Source:t0pP8uZz
    Published:16 May 2008
    7.5
    High

    CVE-2008-2278

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pdetails action.

    Source:t0pP8uZz
    Published:16 May 2008
    7.5
    High

    CVE-2008-2277

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.

    Source:t0pP8uZz
    Published:16 May 2008
    6.8
    Medium

    CVE-2008-2276

    Last Modified: 2 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.

    Source:USH
    Published:22 Mar 2008
    7.5
    High

    CVE-2008-2270

    Last Modified: 29 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to execute arbitrary PHP code via a URL in the (1) main_page_directory and (2) page_to_include parameters in template\index.php.

    Source:HaCkeR_EgY
    Published:16 May 2008
    7.5
    High

    CVE-2008-2269

    Last Modified: 23 Apr 2026

    AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE.

    Source:t0pP8uZz
    Published:16 May 2008
    7.5
    High

    CVE-2008-2267

    Last Modified: 2 Dec 2016

    Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6) .php5, or (7) .jar, then accessing it via a direct request to the file in modules/FileManager/postlet/.

    Source:EgiX
    Published:16 May 2008