5
    Medium

    CVE-2008-1799

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in thumbnails.php in sabros.us 1.75 allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter.

    Source:HaCkeR_EgY
    Published:15 Apr 2008
    7.5
    High

    CVE-2008-1798

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cal[lng] parameter.

    Source:w0cker
    Published:15 Apr 2008
    4.3
    Medium

    CVE-2008-1795

    Last Modified: 10 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to webapps/blackboard/execute/viewCatalog or (2) the data__announcements___pk1_pk2__subject parameter in an ADD action to bin/common/announcement.pl.

    Source:Knight4vn
    Published:15 Apr 2008
    7.5
    High

    CVE-2008-1791

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the ladderid parameter.

    Source:t0pP8uZz
    Published:15 Apr 2008
    6.5
    Medium

    CVE-2008-1790

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOTE: remote exploitation is facilitated by a separate SQL injection vulnerability.

    Source:t0pP8uZz
    Published:15 Apr 2008
    6.8
    Medium

    CVE-2008-1789

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.

    Source:t0pP8uZz
    Published:15 Apr 2008
    7.5
    High

    CVE-2008-1788

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: some of these details are obtained from third party information.

    Source:t0pP8uZz
    Published:15 Apr 2008
    4.3
    Medium

    CVE-2008-1787

    Last Modified: 12 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Poplar Gedcom Viewer 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) text and (2) ul parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:15 Apr 2008
    5.5
    Medium

    CVE-2008-1785

    Last Modified: 23 Apr 2026

    delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter.

    Source:t0pP8uZz
    Published:15 Apr 2008
    7.5
    High

    CVE-2008-1784

    Last Modified: 23 Apr 2026

    Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/.

    Source:t0pP8uZz
    Published:15 Apr 2008
    6.4
    Medium

    CVE-2008-1783

    Last Modified: 23 Apr 2026

    Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php.

    Source:t0pP8uZz
    Published:15 Apr 2008
    5
    Medium

    CVE-2008-1782

    Last Modified: 24 Nov 2016

    phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive files via the file parameter.

    Source:Stack
    Published:15 Apr 2008
    6.8
    Medium

    CVE-2008-1776

    Last Modified: 17 Nov 2016

    PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote attackers to execute arbitrary PHP code via a URL in the PATH_TO_CODE parameter.

    Source:w0cker
    Published:14 Apr 2008
    7.5
    High

    CVE-2008-1774

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Guido Landi
    Published:14 Apr 2008
    6.8
    Medium

    CVE-2008-1773

    Last Modified: 24 Nov 2016

    PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:RoMaNcYxHaCkEr
    Published:14 Apr 2008
    5
    Medium

    CVE-2008-1772

    Last Modified: 23 Apr 2026

    iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.

    Source:t0pP8uZz
    Published:14 Apr 2008
    9.3
    Critical

    CVE-2008-1770

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.

    Source:cocoruder
    Published:4 Jun 2008
    6.8
    Medium

    CVE-2008-1769

    Last Modified: 23 Apr 2026

    VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.

    Source:j0rgan
    Published:24 Apr 2008
    7.5
    High

    CVE-2008-1767

    Last Modified: 22 Feb 2014

    Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.

    Source:Anthony de Almeida Lopes
    Published:10 Apr 2008
    9.3
    Critical

    CVE-2008-1765

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.

    Source:c0ntex
    Published:23 Apr 2008
    7.5
    High

    CVE-2008-1763

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in _blogadata/include/sond_result.php in Blogator-script 0.95 allows remote attackers to execute arbitrary SQL commands via the id_art parameter.

    Source:Virangar Security
    Published:12 Apr 2008
    9.3
    Critical

    CVE-2008-1762

    Last Modified: 18 Dec 2016

    Opera before 9.27 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted scaled image pattern in an HTML CANVAS element, which triggers memory corruption.

    Source:Michal Zalewski
    Published:12 Apr 2008
    6.8
    Medium

    CVE-2008-1760

    Last Modified: 17 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the incl_page parameter in (1) struct_admin.php, (2) struct_admin_blog.php, and (3) struct_main.php in _blogadata/include.

    Source:JIKO
    Published:12 Apr 2008
    7.5
    High

    CVE-2008-1759

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php, a different vector than CVE-2007-4922.

    Source:Houssamix
    Published:12 Apr 2008
    7.5
    High

    CVE-2008-1758

    Last Modified: 17 Nov 2016

    SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID parameter to index.php.

    Source:Stack
    Published:12 Apr 2008
    4.3
    Medium

    CVE-2008-1757

    Last Modified: 12 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the VIEW parameter.

    Source:H-T Team
    Published:12 Apr 2008
    5
    Medium

    CVE-2008-1755

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.

    Source:HaCkeR_EgY
    Published:11 Apr 2008
    6.8
    Medium

    CVE-2008-1751

    Last Modified: 21 Nov 2016

    Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) language and (2) lang parameters.

    Source:dun
    Published:11 Apr 2008
    7.5
    High

    CVE-2008-1750

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.

    Source:irvian
    Published:11 Apr 2008
    7.5
    High

    CVE-2008-1733

    Last Modified: 13 Feb 2014

    SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter to index.php.

    Source:MantiS
    Published:11 Apr 2008
    7.5
    High

    CVE-2008-1732

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute arbitrary SQL commands via the matchid parameter in a dupa action.

    Source:0in
    Published:11 Apr 2008
    5
    Medium

    CVE-2008-1730

    Last Modified: 21 Nov 2016

    Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Photo Gallery Site Script), as of 20080411, allows remote attackers to read arbitrary local files via directory traversal sequences in the path parameter.

    Source:JIKO
    Published:11 Apr 2008
    7.5
    High

    CVE-2008-1727

    Last Modified: 23 Apr 2026

    KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts.

    Source:t0pP8uZz
    Published:11 Apr 2008
    6.8
    Medium

    CVE-2008-1726

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php.

    Source:Virangar Security
    Published:11 Apr 2008
    9
    Critical

    CVE-2008-1725

    Last Modified: 23 Apr 2026

    The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from third party information.

    Source:shinnai
    Published:11 Apr 2008
    9.3
    Critical

    CVE-2008-1724

    Last Modified: 21 Nov 2016

    Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Server before 4.6.1 Hotfix 20 allows remote attackers to execute arbitrary code via a long remoteFile parameter.

    Source:Patrick Webster
    Published:11 Apr 2008
    7.5
    High

    CVE-2008-1721

    Last Modified: 13 Feb 2014

    Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.

    Source:Justin Ferguson
    Published:9 Apr 2008
    6.8
    Medium

    CVE-2008-1715

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.

    Source:NTOS-Team
    Published:9 Apr 2008
    6.8
    Medium

    CVE-2008-1714

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:9 Apr 2008
    5
    Medium

    CVE-2008-1713

    Last Modified: 23 Apr 2026

    MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp).

    Source:Ray
    Published:9 Apr 2008
    7.5
    High

    CVE-2008-1712

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_weblog.php in mxBB mx_blogs 2.0.0 beta allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Source:bd0rk
    Published:9 Apr 2008
    5
    Medium

    CVE-2008-1711

    Last Modified: 17 Nov 2016

    Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Source:t0pP8uZz
    Published:9 Apr 2008
    9.3
    Critical

    CVE-2008-1709

    Last Modified: 17 Nov 2016

    Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long malformed Project line beginning with a 'Project("{}") =' sequence, probably a different vector than CVE-2008-0250.

    Source:shinnai
    Published:9 Apr 2008
    4.3
    Medium

    CVE-2008-1702

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obtain sensitive information via a full pathname in the file parameter. NOTE: some of these details are obtained from third party information.

    Source:Jerome Athias
    Published:8 Apr 2008
    10
    Critical

    CVE-2008-1697

    Last Modified: 25 May 2017

    Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain topology/homeBaseView request. NOTE: some of these details are obtained from third party information.

    Source:muts
    Published:8 Apr 2008
    3.7
    Low

    CVE-2008-1696

    Last Modified: 17 Nov 2016

    Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the prefixdir parameter.

    Source:w0cker
    Published:8 Apr 2008
    10
    Critical

    CVE-2008-1690

    Last Modified: 13 Jul 2017

    WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a long URI in HTTP requests to TCP port 801. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:7 Apr 2008
    6.8
    Medium

    CVE-2008-1682

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter.

    Source:NoGe
    Published:4 Apr 2008
    5
    Medium

    CVE-2008-1680

    Last Modified: 16 Nov 2016

    PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.

    Source:Inphex
    Published:4 Apr 2008
    10
    Critical

    CVE-2008-1661

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.

    Source:Metasploit
    Published:4 Jun 2008