4.3
    Medium

    CVE-2008-2127

    Last Modified: 28 Nov 2016

    Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via the what parameter. NOTE: some of these details are obtained from third party information.

    Source:RoMaNcYxHaCkEr
    Published:9 May 2008
    4.3
    Medium

    CVE-2008-2126

    Last Modified: 19 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to index.php and the (2) returnURL parameter to tux-login.php.

    Source:Hadi Kiamarsi
    Published:9 May 2008
    7.5
    High

    CVE-2008-2125

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.

    Source:HaCkeR_EgY
    Published:9 May 2008
    7.5
    High

    CVE-2008-2124

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter.

    Source:InjEctOr5
    Published:9 May 2008
    4.3
    Medium

    CVE-2008-2123

    Last Modified: 19 Feb 2014

    Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script or HTML via (1) a "<>" sequence in the ~service parameter to wgate.dll, or (2) Javascript splicing in the query string, a different vector than CVE-2006-5114.

    Source:Portcullis
    Published:9 May 2008
    4.3
    Medium

    CVE-2008-2119

    Last Modified: 5 Dec 2016

    Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.

    Source:Armando Oliveira
    Published:4 Jun 2008
    7.5
    High

    CVE-2008-2118

    Last Modified: 18 Feb 2014

    SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:hadihadi
    Published:8 May 2008
    4.3
    Medium

    CVE-2008-2117

    Last Modified: 18 Feb 2014

    Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.

    Source:hadihadi
    Published:8 May 2008
    4.4
    Medium

    CVE-2008-2116

    Last Modified: 2 Dec 2016

    Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.

    Source:Virangar Security
    Published:8 May 2008
    4.3
    Medium

    CVE-2008-2115

    Last Modified: 2 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.

    Source:Virangar Security
    Published:8 May 2008
    7.5
    High

    CVE-2008-2114

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Source:t0pP8uZz
    Published:8 May 2008
    7.5
    High

    CVE-2008-2113

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:InjEctOr5
    Published:8 May 2008
    9.3
    Critical

    CVE-2008-2111

    Last Modified: 19 Feb 2014

    The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.

    Source:Sowhat
    Published:7 May 2008
    7.5
    High

    CVE-2008-2110

    Last Modified: 19 Feb 2014

    Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.

    Source:CrAzY CrAcKeR
    Published:7 May 2008
    6.8
    Medium

    CVE-2008-2106

    Last Modified: 18 Feb 2014

    Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative value.

    Source:Luigi Auriemma
    Published:7 May 2008
    6.8
    Medium

    CVE-2008-2096

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to a site-specific component name such as link.php or backlinkspider.php.

    Source:K-159
    Published:7 May 2008
    7.5
    High

    CVE-2008-2095

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.

    Source:cO2
    Published:6 May 2008
    7.5
    High

    CVE-2008-2094

    Last Modified: 28 Aug 2010

    SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:[]0iZy5
    Published:6 May 2008
    7.5
    High

    CVE-2008-2093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.

    Source:$hur!k'n
    Published:6 May 2008
    7.8
    High

    CVE-2008-2092

    Last Modified: 7 Feb 2014

    Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

    Source:sipherr
    Published:6 May 2008
    7.5
    High

    CVE-2008-2091

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the i parameter.

    Source:Crackers_Child
    Published:6 May 2008
    7.5
    High

    CVE-2008-2088

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.

    Source:JIKO
    Published:6 May 2008
    6.8
    Medium

    CVE-2008-2087

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.

    Source:K-159
    Published:6 May 2008
    7.5
    High

    CVE-2008-2084

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a listarticles action.

    Source:Cr@zy_King
    Published:5 May 2008
    6.8
    Medium

    CVE-2008-2083

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:K-159
    Published:5 May 2008
    4.3
    Medium

    CVE-2008-2082

    Last Modified: 2 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web script or HTML via the module parameter, which leaks the path in an error message.

    Source:Khashayar Fereidani
    Published:5 May 2008
    9
    Critical

    CVE-2008-2081

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Source:Khashayar Fereidani
    Published:5 May 2008
    7.5
    High

    CVE-2008-2076

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the style parameter.

    Source:Khashayar Fereidani
    Published:5 May 2008
    7.5
    High

    CVE-2008-2074

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities Harris Yusuf Arifin Harris Wap Chat 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the sysFileDir parameter to (1) eng.writeMsg.php, (2) eng.adCreate.php, (3) eng.adCreateSave.php, (4) eng.adDispByTypeOptions.php, (5) eng.createRoom.php, (6) eng.forward.php, (7) eng.pageLogout.php, (8) eng.resultMember.php, (9) eng.roomDeleteConfirm.php, (10) eng.saveNewRoom.php, and (11) eng.searchMember.php in src/.

    Source:k1n9k0ng
    Published:5 May 2008
    7.5
    High

    CVE-2008-2073

    Last Modified: 2 Dec 2016

    Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

    Source:Khashayar Fereidani
    Published:5 May 2008
    4.3
    Medium

    CVE-2008-2072

    Last Modified: 2 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to inject arbitrary web script or HTML via the l parameter, a different vector than CVE-2006-3260.

    Source:Khashayar Fereidani
    Published:5 May 2008
    4.3
    Medium

    CVE-2008-2070

    Last Modified: 20 Feb 2014

    The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.

    Source:Matteo Carli
    Published:12 May 2008
    9.3
    Critical

    CVE-2008-2069

    Last Modified: 24 Nov 2016

    Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.

    Source:Juan Yacubian
    Published:2 May 2008
    7.5
    High

    CVE-2008-2065

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary SQL commands via the catagorie parameter.

    Source:ProgenTR
    Published:2 May 2008
    7.5
    High

    CVE-2008-2063

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in browse.videos.php in Joovili 3.1 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:HaCkeR_EgY
    Published:2 May 2008
    4.3
    Medium

    CVE-2008-2048

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject arbitrary web script or HTML via the sayfa parameter.

    Source:U238
    Published:1 May 2008
    7.5
    High

    CVE-2008-2047

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hpz/profil.asp and (2) hpz/prodetail.asp.

    Source:U238
    Published:1 May 2008
    4.3
    Medium

    CVE-2008-2046

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Source:CWH Underground
    Published:1 May 2008
    5
    Medium

    CVE-2008-2045

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

    Source:Roberto Suggi Liverani
    Published:1 May 2008
    7.5
    High

    CVE-2008-2044

    Last Modified: 31 Jan 2014

    includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of the true boolean literal, which allows remote attackers to bypass authentication and execute arbitrary code by setting this variable to 1, as demonstrated by uploading a PHP script via an add action to projects_site/uploadfile.php.

    Source:RawSecurity.org
    Published:1 May 2008
    7.5
    High

    CVE-2008-2040

    Last Modified: 17 Feb 2014

    Stack-based buffer overflow in the HTTP::getAuthUserPass function (core/common/http.cpp) in Peercast 0.1218 and gnome-peercast allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Basic Authentication string with a long (1) username or (2) password.

    Source:Nico Golde
    Published:30 Apr 2008
    3.5
    Low

    CVE-2008-2037

    Last Modified: 14 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in EditeurScripts EsContacts 1.0 allow remote authenticated users to inject arbitrary web script or HTML via the msg parameter to (1) login.php, (2) importer.php, (3) add_groupe.php, (4) contacts.php, (5) groupes.php, and (6) search.php.

    Source:ZoRLu
    Published:30 Apr 2008
    7.5
    High

    CVE-2008-2036

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL commands via the poll_id parameter in a poll action.

    Source:S@BUN
    Published:30 Apr 2008
    5
    Medium

    CVE-2008-2032

    Last Modified: 20 Apr 2017

    The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:LiquidWorm
    Published:30 Apr 2008
    5
    Medium

    CVE-2008-2031

    Last Modified: 23 Apr 2026

    VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Alfons Luja
    Published:30 Apr 2008
    4.3
    Medium

    CVE-2008-2030

    Last Modified: 17 Feb 2014

    Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Alberto Cuesta Partida
    Published:30 Apr 2008
    6.8
    Medium

    CVE-2008-2029

    Last Modified: 24 Nov 2016

    Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary SQL commands via the xtr parameter in a userinfo action to index.php.

    Source:girex
    Published:30 Apr 2008
    4.3
    Medium

    CVE-2008-2028

    Last Modified: 24 Nov 2016

    miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to the glang parameter in a registernew action to index.php, which leaks the path in an error message.

    Source:girex
    Published:30 Apr 2008
    4.3
    Medium

    CVE-2008-2024

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

    Source:girex
    Published:30 Apr 2008
    7.5
    High

    CVE-2008-2023

    Last Modified: 25 Nov 2016

    Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel.asp and the (3) attachmentid parameter to forums/attach-file.asp.

    Source:BugReport.IR
    Published:30 Apr 2008