4.3
    Medium

    CVE-2008-2022

    Last Modified: 25 Nov 2016

    Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) toid parameter to send-private-message.asp and the (2) redirect parameter to admin/impersonate.asp. NOTE: vector 2 requires authentication.

    Source:BugReport.IR
    Published:30 Apr 2008
    7.5
    High

    CVE-2008-2019

    Last Modified: 23 Apr 2026

    Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated attack that considers Hamming distances. NOTE: this issue reportedly exists because of an insufficient fix for CVE-2007-3308.

    Published:30 Apr 2008
    4
    Medium

    CVE-2008-2018

    Last Modified: 23 Apr 2026

    The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authenticated users to obtain sensitive information via a comment containing a macro, as demonstrated by a "{user.password}" comment in the profile of the admin user.

    Source:YOUCODE
    Published:30 Apr 2008
    9.3
    Critical

    CVE-2008-2015

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in one control, and the (3) saveRecordedExploreToFile method in a different control. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Source:callAX
    Published:30 Apr 2008
    6.8
    Medium

    CVE-2008-2013

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.

    Source:Kacper
    Published:30 Apr 2008
    7.5
    High

    CVE-2008-2012

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.

    Source:Kacper
    Published:30 Apr 2008
    4.3
    Medium

    CVE-2008-2006

    Last Modified: 12 Feb 2014

    Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a .ics file containing (1) a large 16-bit integer on a TRIGGER line, or (2) a large integer in a COUNT field on an RRULE line.

    Source:Rodrigo Carvalho
    Published:22 May 2008
    5
    Medium

    CVE-2008-2005

    Last Modified: 23 Apr 2026

    The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.

    Source:belay tows
    Published:6 May 2008
    5
    Medium

    CVE-2008-1996

    Last Modified: 12 Feb 2014

    licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connections.

    Source:Milen Rangelov
    Published:8 Apr 2008
    7.5
    High

    CVE-2008-1993

    Last Modified: 24 Nov 2016

    Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.

    Source:BugReport.IR
    Published:27 Apr 2008
    7.5
    High

    CVE-2008-1992

    Last Modified: 24 Nov 2016

    Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName, and To fields.

    Source:BugReport.IR
    Published:27 Apr 2008
    4.3
    Medium

    CVE-2008-1991

    Last Modified: 24 Nov 2016

    Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the field parameter.

    Source:BugReport.IR
    Published:27 Apr 2008
    7.5
    High

    CVE-2008-1990

    Last Modified: 24 Nov 2016

    Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.

    Source:BugReport.IR
    Published:27 Apr 2008
    10
    Critical

    CVE-2008-1989

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.

    Source:by_casper41
    Published:27 Apr 2008
    4.3
    Medium

    CVE-2008-1986

    Last Modified: 17 Feb 2014

    Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

    Source:ZoRLu
    Published:27 Apr 2008
    4.3
    Medium

    CVE-2008-1985

    Last Modified: 27 Oct 2016

    Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.

    Source:ViRuSMaN
    Published:27 Apr 2008
    4.3
    Medium

    CVE-2008-1983

    Last Modified: 16 Feb 2014

    Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.

    Source:ZoRLu
    Published:27 Apr 2008
    7.5
    High

    CVE-2008-1982

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.

    Source:1ten0.0net1
    Published:27 Apr 2008
    5
    Medium

    CVE-2008-1979

    Last Modified: 18 Feb 2014

    The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large integer value used in an increment to TCP port 41523, which triggers a buffer over-read.

    Source:Luigi Auriemma
    Published:27 Apr 2008
    7.5
    High

    CVE-2008-1975

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.

    Source:JIKO
    Published:27 Apr 2008
    4.3
    Medium

    CVE-2008-1974

    Last Modified: 17 Feb 2014

    Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Source:Aria-Security Team
    Published:22 Apr 2008
    9.3
    Critical

    CVE-2008-1973

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

    Source:grzdyl
    Published:27 Apr 2008
    7.5
    High

    CVE-2008-1971

    Last Modified: 22 Nov 2016

    phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.

    Source:t0pP8uZz
    Published:27 Apr 2008
    3.5
    Low

    CVE-2008-1969

    Last Modified: 13 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6) WidgetsTitles parameters to (b) CznCommon/CznCustomContainer.asp, (7) CFTARGET parameter to (c) home.asp, (8) PersonOid parameter to (d) PeopleWeb/Cards/CVCard.asp, (9) DESTLINKOID and PersonOID parameters to (e) PeopleWeb/Cards/PayrollCard.asp, and the (10) FolderTemplateId and (11) FolderTemplateName parameters to (f) PeopleWeb/CznDocFolder/CznDFStartProcess.asp.

    Source:Juan de la Fuente Costa
    Published:27 Apr 2008
    6
    Medium

    CVE-2008-1968

    Last Modified: 13 Feb 2014

    Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.

    Source:Juan de la Fuente Costa
    Published:27 Apr 2008
    4.3
    Medium

    CVE-2008-1967

    Last Modified: 13 Feb 2014

    Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML via the SleUserName parameter.

    Source:Juan de la Fuente Costa
    Published:27 Apr 2008
    9.3
    Critical

    CVE-2008-1965

    Last Modified: 17 Feb 2014

    Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.

    Source:Thomas Pollet
    Published:25 Apr 2008
    7.5
    High

    CVE-2008-1963

    Last Modified: 22 Nov 2016

    PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.

    Source:MajnOoNxHaCkEr
    Published:25 Apr 2008
    6.8
    Medium

    CVE-2008-1962

    Last Modified: 24 Nov 2016

    Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) class parameter to include/functions.inc.php and the (2) file parameter to include/common.inc.php.

    Source:KnocKout
    Published:25 Apr 2008
    7.5
    High

    CVE-2008-1961

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.

    Source:Player
    Published:25 Apr 2008
    6.5
    Medium

    CVE-2008-1958

    Last Modified: 24 Nov 2016

    Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension.

    Source:His0k4
    Published:25 Apr 2008
    7.5
    High

    CVE-2008-1957

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.

    Source:His0k4
    Published:25 Apr 2008
    4.3
    Medium

    CVE-2008-1956

    Last Modified: 14 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter.

    Source:Gerendi Sandor Attila
    Published:25 Apr 2008
    4.3
    Medium

    CVE-2008-1955

    Last Modified: 14 Feb 2014

    Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML via the id parameter. information.

    Source:ZoRLu
    Published:25 Apr 2008
    7.5
    High

    CVE-2008-1954

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Source:t0pP8uZz
    Published:25 Apr 2008
    7.5
    High

    CVE-2008-1939

    Last Modified: 24 Nov 2016

    Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to (b) philboard_newtopic.asp, different vectors than CVE-2007-2641 and CVE-2007-0920.

    Source:U238
    Published:24 Apr 2008
    7.5
    High

    CVE-2008-1936

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action. NOTE: this issue might be site-specific.

    Source:JosS
    Published:24 Apr 2008
    7.5
    High

    CVE-2008-1935

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.

    Source:str0xo
    Published:24 Apr 2008
    7.5
    High

    CVE-2008-1934

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ZoRLu
    Published:24 Apr 2008
    4.3
    Medium

    CVE-2008-1933

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run.

    Source:ilion security
    Published:24 Apr 2008
    7.5
    High

    CVE-2008-1930

    Last Modified: 23 Apr 2026

    The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.

    Published:28 Apr 2008
    7.5
    High

    CVE-2008-1921

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.

    Source:Aria-Security Team
    Published:22 Apr 2008
    7.5
    High

    CVE-2008-1920

    Last Modified: 14 Feb 2014

    Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted personal status message.

    Source:Leon Juranic
    Published:22 Apr 2008
    7.5
    High

    CVE-2008-1919

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.

    Source:Crackers_Child
    Published:22 Apr 2008
    6
    Medium

    CVE-2008-1918

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that 7.00.2 is also affected.

    Source:The:Paradox
    Published:22 Apr 2008
    4.3
    Medium

    CVE-2008-1917

    Last Modified: 14 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in AMFPHP 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) class parameter to (a) methodTable.php, (b) code.php, and (c) details.php in browser/; and the (2) location parameter to browser/code.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Alberto Cuesta Partida
    Published:22 Apr 2008
    7.5
    High

    CVE-2008-1915

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:U238
    Published:22 Apr 2008
    10
    Critical

    CVE-2008-1914

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:22 Apr 2008
    7.5
    High

    CVE-2008-1913

    Last Modified: 30 Mar 2017

    SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the new parameter in a new action.

    Source:cO2
    Published:22 Apr 2008
    9.3
    Critical

    CVE-2008-1912

    Last Modified: 24 Nov 2016

    Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.

    Source:securfrog
    Published:22 Apr 2008