7.5
    High

    CVE-2008-2265

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter.

    Source:HaCkeR_EgY
    Published:16 May 2008
    4.3
    Medium

    CVE-2008-2264

    Last Modified: 20 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in CyrixMED 1.4 allows remote attackers to inject arbitrary web script or HTML via the msg_erreur parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:16 May 2008
    7.5
    High

    CVE-2008-2263

    Last Modified: 29 Nov 2016

    SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: linking.page.php is commonly renamed to link.php, links.php, etc.

    Source:HaCkeR_EgY
    Published:16 May 2008
    9.3
    Critical

    CVE-2008-2245

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.

    Source:Ac!dDrop
    Published:13 Aug 2008
    10
    Critical

    CVE-2008-2240

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.

    Source:Metasploit
    Published:22 May 2008
    9.3
    Critical

    CVE-2008-2228

    Last Modified: 28 Nov 2016

    PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.

    Source:RoMaNcYxHaCkEr
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2227

    Last Modified: 19 Feb 2014

    Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Matrix86
    Published:14 May 2008
    7.5
    High

    CVE-2008-2225

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands via the systemId parameter.

    Source:InjEctOr5
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2224

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _saz[settings][site_dir] parameter to layouts/default/header.saz.php and the (2) _saz[settings][site_url] parameter to admin/alayouts/default/pages/login.php.

    Source:RoMaNcYxHaCkEr
    Published:14 May 2008
    7.5
    High

    CVE-2008-2223

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Source:Saime
    Published:14 May 2008
    7.5
    High

    CVE-2008-2222

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in login.php in EQdkp 1.3.2f allows remote attackers to bypass EQdkp user authentication via the user_id parameter.

    Source:vortfu
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2220

    Last Modified: 2 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[LANGUAGE_CPATH] parameter to modules/forum/embedforum.php and the (2) CONFIG[BASE_PATH] parameter to modules/scorm/lib.inc.php, different vectors than CVE-2006-4448.

    Source:RoMaNcYxHaCkEr
    Published:14 May 2008
    4.3
    Medium

    CVE-2008-2219

    Last Modified: 18 Feb 2014

    Cross-site scripting (XSS) vulnerability in install.php in C-News.fr C-News 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the etape parameter.

    Source:ZoRLu
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2217

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_imgpath parameter.

    Source:Houssamix
    Published:14 May 2008
    9
    Critical

    CVE-2008-2216

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to upload arbitrary files to tmp/uploads.

    Source:GoLd_M
    Published:14 May 2008
    5
    Medium

    CVE-2008-2215

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to (1) src/yopy_sync.php and (2) system-logger/print_logs.php.

    Source:GoLd_M
    Published:14 May 2008
    10
    Critical

    CVE-2008-2214

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long community string in an SNMP TRAP packet.

    Source:Praveen Darshanam
    Published:14 May 2008
    4.3
    Medium

    CVE-2008-2202

    Last Modified: 4 Apr 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to index.php in a search action.

    Source:Khashayar Fereidani
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2199

    Last Modified: 25 Nov 2016

    PHP remote file inclusion vulnerability in kmitaadmin/kmitam/htmlcode.php in Kmita Mail 3.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:K-159
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2198

    Last Modified: 25 Nov 2016

    PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:K-159
    Published:14 May 2008
    7.5
    High

    CVE-2008-2197

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php.

    Source:HaCkeR_EgY
    Published:14 May 2008
    4.3
    Medium

    CVE-2008-2196

    Last Modified: 19 Feb 2014

    Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.

    Source:Khashayar Fereidani
    Published:14 May 2008
    6.5
    Medium

    CVE-2008-2195

    Last Modified: 25 Nov 2016

    Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.

    Source:EgiX
    Published:14 May 2008
    7.5
    High

    CVE-2008-2194

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.

    Source:EgiX
    Published:14 May 2008
    7.5
    High

    CVE-2008-2193

    Last Modified: 25 Nov 2016

    PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the site parameter.

    Source:Silver
    Published:14 May 2008
    10
    Critical

    CVE-2008-2192

    Last Modified: 25 Nov 2016

    Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inject arbitrary PHP code into box/MiniChat/data/shouts.php via the shout parameter.

    Source:Cod3rZ
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2191

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_term action to index.php.

    Source:K-159
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2190

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported that 5.0 and earlier are also affected.

    Source:K-159
    Published:14 May 2008
    6.8
    Medium

    CVE-2008-2189

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:K-159
    Published:14 May 2008
    4.3
    Medium

    CVE-2008-2188

    Last Modified: 18 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to (b) header.php.

    Source:Khashayar Fereidani
    Published:13 May 2008
    4.3
    Medium

    CVE-2008-2187

    Last Modified: 18 Feb 2014

    Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7 GT Rev.01 allows remote attackers to inject arbitrary web script or HTML via the level parameter in a redirect action, possibly involving interface/redirect.htm.php.

    Source:Khashayar Fereidani
    Published:13 May 2008
    4.3
    Medium

    CVE-2008-2186

    Last Modified: 5 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:Hadi Kiamarsi
    Published:13 May 2008
    4.3
    Medium

    CVE-2008-2185

    Last Modified: 25 Nov 2016

    Directory traversal vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to include arbitrary local files via directory traversal sequences in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:His0k4
    Published:13 May 2008
    7.5
    High

    CVE-2008-2184

    Last Modified: 25 Nov 2016

    Multiple SQL injection vulnerabilities in SMartBlog (aka SMBlog) 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) mois, (2) an, (3) jour, and (4) id parameters to index.php, and the (5) login parameter to gestion/logon.php, different vectors than CVE-2008-2183. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:His0k4
    Published:13 May 2008
    7.5
    High

    CVE-2008-2183

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to execute arbitrary SQL commands via the idt parameter.

    Source:His0k4
    Published:13 May 2008
    4.3
    Medium

    CVE-2008-2181

    Last Modified: 25 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbitrary web script or HTML via the (1) search_text and (2) search_category parameters. NOTE: the XSS reportedly occurs in a forced SQL error message. NOTE: some of these details are obtained from third party information.

    Source:InjEctOr5
    Published:13 May 2008
    6.8
    Medium

    CVE-2008-2180

    Last Modified: 25 Nov 2016

    Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) admin_username parameter (aka the username field) to admin/index.php and the (2) search_text and (3) search_category parameters to search.php. NOTE: some of these details are obtained from third party information.

    Source:InjEctOr5
    Published:13 May 2008
    6.8
    Medium

    CVE-2008-2177

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to show.php and the (2) login parameter to admin.php.

    Source:InjEctOr5
    Published:13 May 2008
    7.5
    High

    CVE-2008-2175

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:His0k4
    Published:13 May 2008
    4.3
    Medium

    CVE-2008-2168

    Last Modified: 19 Feb 2014

    Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

    Source:Yaniv Miron
    Published:8 May 2008
    4.3
    Medium

    CVE-2008-2167

    Last Modified: 19 Feb 2014

    Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page.

    Source:Deniz Cevik
    Published:13 May 2008
    4.3
    Medium

    CVE-2008-2162

    Last Modified: 19 Feb 2014

    Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page.

    Source:Deniz Cevik
    Published:12 May 2008
    10
    Critical

    CVE-2008-2161

    Last Modified: 24 Nov 2016

    Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information.

    Source:tixxDZ
    Published:12 May 2008
    10
    Critical

    CVE-2008-2158

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the Command Line Interface process in the Server Agent in EMC AlphaStor 3.1 SP1 for Windows allow remote attackers to execute arbitrary code via crafted TCP packets to port 41025.

    Source:Metasploit
    Published:29 May 2008
    5
    Medium

    CVE-2008-2138

    Last Modified: 20 Feb 2014

    Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.

    Source:Deniz Cevik
    Published:12 May 2008
    7.5
    High

    CVE-2008-2135

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php.

    Source:Virangar Security
    Published:9 May 2008
    7.5
    High

    CVE-2008-2132

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL commands via the cat_fldAuto parameter.

    Source:InjEctOr5
    Published:9 May 2008
    7.5
    High

    CVE-2008-2130

    Last Modified: 19 Feb 2014

    SQL injection vulnerability in poll_vote.php in iGaming CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Cod3rZ
    Published:9 May 2008
    6.8
    Medium

    CVE-2008-2129

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in index.php in Galleristic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:cOndemned
    Published:9 May 2008
    7.5
    High

    CVE-2008-2128

    Last Modified: 28 Nov 2016

    PHP remote file inclusion vulnerability in templates/header.php in CMS Faethon 2.2 Ultimate allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter, a different vulnerability than CVE-2006-5588 and CVE-2006-3185.

    Source:RoMaNcYxHaCkEr
    Published:9 May 2008