6.8
    Medium

    CVE-2008-1911

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a cookpass cookie.

    Source:girex
    Published:21 Apr 2008
    10
    Critical

    CVE-2008-1910

    Last Modified: 21 Nov 2016

    Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers to execute arbitrary code via a malformed opcode 0x52 request to TCP port 3050. NOTE: this might overlap CVE-2007-5243 or CVE-2007-5244.

    Source:Liu Zhen Hua
    Published:21 Apr 2008
    7.5
    High

    CVE-2008-1909

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:parad0x
    Published:21 Apr 2008
    7.5
    High

    CVE-2008-1908

    Last Modified: 21 Nov 2016

    Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php.

    Source:BugReport.IR
    Published:21 Apr 2008
    7.5
    High

    CVE-2008-1907

    Last Modified: 21 Nov 2016

    Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_product, (2) id_manufacturer, and (3) id_category parameters to unspecified components. NOTE: this probably overlaps CVE-2007-2959 and CVE-2007-2890.

    Source:BugReport.IR
    Published:21 Apr 2008
    4.3
    Medium

    CVE-2008-1906

    Last Modified: 21 Nov 2016

    Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a view.year action.

    Source:BugReport.IR
    Published:21 Apr 2008
    7.5
    High

    CVE-2008-1904

    Last Modified: 23 Apr 2026

    Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.

    Source:t0pP8uZz
    Published:21 Apr 2008
    7.5
    High

    CVE-2008-1903

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

    Source:RoMaNcYxHaCkEr
    Published:21 Apr 2008
    9.3
    Critical

    CVE-2008-1898

    Last Modified: 23 Apr 2026

    A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.

    Source:Shennan Wang
    Published:21 Apr 2008
    4.3
    Medium

    CVE-2008-1896

    Last Modified: 22 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.

    Source:BugReport.IR
    Published:18 Apr 2008
    7.5
    High

    CVE-2008-1895

    Last Modified: 22 Nov 2016

    Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action.

    Source:BugReport.IR
    Published:18 Apr 2008
    7.5
    High

    CVE-2008-1893

    Last Modified: 14 Feb 2014

    PHP remote file inclusion vulnerability in index.php in W2B Online Banking allows remote attackers to execute arbitrary PHP code via a URL in the ilang parameter.

    Source:THuM4N
    Published:18 Apr 2008
    7.5
    High

    CVE-2008-1889

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in viewcat.php in XplodPHP AutoTutorials 2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:cO2
    Published:18 Apr 2008
    4.3
    Medium

    CVE-2008-1888

    Last Modified: 13 Feb 2014

    Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.

    Source:OneIdBeagl3
    Published:18 Apr 2008
    7.5
    High

    CVE-2008-1886

    Last Modified: 23 Apr 2026

    The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by calculating the required KeyCode. NOTE: this can be used by arbitrary web sites to host exploit code that targets this control.

    Source:Simon Ryeo
    Published:18 Apr 2008
    6.8
    Medium

    CVE-2008-1885

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a .. (dot dot) in the SkinPath parameter and a .zip URL in the HttpSkin parameter. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Source:Simon Ryeo
    Published:18 Apr 2008
    6.8
    Medium

    CVE-2008-1881

    Last Modified: 23 Nov 2016

    Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.

    Source:j0rgan
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1878

    Last Modified: 24 Nov 2016

    Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

    Source:Guido Landi
    Published:17 Apr 2008
    6.8
    Medium

    CVE-2008-1876

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[files][functions_page] parameter.

    Source:Cr@zy_King
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1875

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter.

    Source:t0pP8uZz
    Published:17 Apr 2008
    6.5
    Medium

    CVE-2008-1874

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to execute arbitrary SQL commands via the reed parameter.

    Source:t0pP8uZz
    Published:17 Apr 2008
    4.3
    Medium

    CVE-2008-1873

    Last Modified: 12 Feb 2014

    Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary web script or HTML via a CSS property in the STYLE attribute of a DIV element in the mensaje parameter. NOTE: some of these details are obtained from third party information.

    Source:Jose Luis Zayas
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1872

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party information.

    Source:t0pP8uZz
    Published:17 Apr 2008
    6.5
    Medium

    CVE-2008-1871

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Source:t0pP8uZz
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1870

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1869

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: this issue might be site-specific.

    Source:S@BUN
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1868

    Last Modified: 23 Apr 2026

    admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.

    Source:JIKO
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1867

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.

    Source:parad0x
    Published:17 Apr 2008
    9
    Critical

    CVE-2008-1866

    Last Modified: 23 Apr 2026

    admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

    Source:JIKO
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1864

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL commands via the project parameter.

    Source:t0pP8uZz
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1863

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:17 Apr 2008
    6.8
    Medium

    CVE-2008-1862

    Last Modified: 21 Nov 2016

    ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or (2) COOKIE variables, a different vector than CVE-2006-4488. NOTE: this can be leveraged to conduct PHP remote file inclusion attacks via a URL in the (a) new_exbb[home_path] or (b) exbb[home_path] parameter to modules/threadstop/threadstop.php.

    Source:The:Paradox
    Published:17 Apr 2008
    5.1
    Medium

    CVE-2008-1861

    Last Modified: 21 Nov 2016

    Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the exbb[default_lang] parameter.

    Source:The:Paradox
    Published:17 Apr 2008
    9.3
    Critical

    CVE-2008-1860

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.

    Source:girex
    Published:17 Apr 2008
    7.5
    High

    CVE-2008-1859

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Source:t0pP8uZz
    Published:16 Apr 2008
    7.5
    High

    CVE-2008-1858

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:Lidloses_Auge
    Published:16 Apr 2008
    6.8
    Medium

    CVE-2008-1857

    Last Modified: 24 Nov 2016

    Multiple directory traversal vulnerabilities in viewsource.php in Make our Life Easy (Mole) 2.1.0 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) dirn and (2) fname parameters.

    Source:GoLd_M
    Published:16 Apr 2008
    5.1
    Medium

    CVE-2008-1856

    Last Modified: 24 Nov 2016

    plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by placing directory traversal sequences into the maps_type configuration setting, and then sending a request to maps_view.php, which causes plugins/maps/map.main.class.php to use the modified configuration.

    Source:EgiX
    Published:16 Apr 2008
    5
    Medium

    CVE-2008-1855

    Last Modified: 23 Apr 2026

    FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot (PrP), allows remote attackers to corrupt memory and cause a denial of service (CMA Framework service crash) via a long invalid method in requests for the /spin//AVClient//AVClient.csp URI, a different vulnerability than CVE-2006-5274.

    Source:muts
    Published:16 Apr 2008
    5
    Medium

    CVE-2008-1854

    Last Modified: 12 Feb 2014

    Unspecified vulnerability in SmarterMail Web Server (SMWebSvr.exe) in SmarterMail 5.0.2999 allows remote attackers to cause a denial of service (service termination) via a long HTTP (1) GET, (2) HEAD, (3) PUT, (4) POST, or (5) TRACE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ryujin
    Published:16 Apr 2008
    5
    Medium

    CVE-2008-1849

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter in a show_error action.

    Source:Houssamix
    Published:16 Apr 2008
    4.3
    Medium

    CVE-2008-1848

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter in a show_error action to index.php.

    Source:Houssamix
    Published:16 Apr 2008
    7.5
    High

    CVE-2008-1847

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Cr@zy_King
    Published:16 Apr 2008
    7.5
    High

    CVE-2008-1844

    Last Modified: 13 Feb 2014

    SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter.

    Source:The-0utl4w
    Published:16 Apr 2008
    7.5
    High

    CVE-2008-1843

    Last Modified: 13 Feb 2014

    SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via the age_to parameter in a browsebyCat action.

    Source:The-0utl4w
    Published:16 Apr 2008
    10
    Critical

    CVE-2008-1842

    Last Modified: 17 Feb 2014

    Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.

    Source:Luigi Auriemma
    Published:16 Apr 2008
    7.5
    High

    CVE-2008-1838

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.

    Source:SoSo H H
    Published:16 Apr 2008
    9.3
    Critical

    CVE-2008-1802

    Last Modified: 28 Nov 2016

    Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect request with modified length fields.

    Source:Guido Landi
    Published:7 May 2008
    9.3
    Critical

    CVE-2008-1801

    Last Modified: 28 Nov 2016

    Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.

    Source:Guido Landi
    Published:7 May 2008
    4.3
    Medium

    CVE-2008-1800

    Last Modified: 12 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in DivXDB 2002 0.94b allow remote attackers to inject arbitrary web script or HTML via the (1) choice, (2) _page_, (3) zone_admin, (4) general_search, and (5) import parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:15 Apr 2008