7.5
    High

    CVE-2008-1651

    Last Modified: 16 Nov 2016

    Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:Khashayar Fereidani
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1650

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter in an edp_Help_Internal_News action.

    Source:Khashayar Fereidani
    Published:2 Apr 2008
    4.3
    Medium

    CVE-2008-1649

    Last Modified: 16 Nov 2016

    Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action.

    Source:Khashayar Fereidani
    Published:2 Apr 2008
    9.3
    Critical

    CVE-2008-1647

    Last Modified: 23 Apr 2026

    The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party information.

    Source:callAX
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1646

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.

    Source:BL4CK
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1645

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot dot) in the filename parameter.

    Source:GoLd_M
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1641

    Last Modified: 12 Feb 2014

    SQL injection vulnerability in default.asp in EfesTECH Video 5.0 allows remote attackers to execute arbitrary SQL commands via the catID parameter.

    Source:RMx
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1640

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the view_id parameter in an ansicht action.

    Source:anonymous
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1639

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.

    Source:Khashayar Fereidani
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1635

    Last Modified: 24 Nov 2016

    Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.

    Source:Cr@zy_King
    Published:2 Apr 2008
    6.8
    Medium

    CVE-2008-1625

    Last Modified: 23 Apr 2026

    aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.

    Source:ryujin
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1624

    Last Modified: 16 Nov 2016

    Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xPage parameter.

    Source:v0l4arrra
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1623

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:S@BUN
    Published:2 Apr 2008
    4.3
    Medium

    CVE-2008-1621

    Last Modified: 10 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ivan Sanchez
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1620

    Last Modified: 11 Feb 2014

    Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote attackers to read or overwrite arbitrary files via a ... (dot dot dot) in the filename.

    Source:Luigi Auriemma
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1613

    Last Modified: 24 Nov 2016

    SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter.

    Source:IRM Plc.
    Published:21 Apr 2008
    10
    Critical

    CVE-2008-1611

    Last Modified: 24 Nov 2016

    Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request.

    Source:b33f
    Published:1 Apr 2008
    7.5
    High

    CVE-2008-1610

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long mode field in a read or write request.

    Source:npn
    Published:1 Apr 2008
    6.8
    Medium

    CVE-2008-1609

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) website parameter to (a) forum.php, (b) headlines.php, and (c) main.php in forum/, and (2) main_dir parameter to forum/forum.php. NOTE: other main_dir vectors are already covered by CVE-2006-7127.

    Source:Kacper
    Published:1 Apr 2008
    6.8
    Medium

    CVE-2008-1607

    Last Modified: 10 Feb 2014

    SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote attackers to execute arbitrary SQL commands via the haber parameter.

    Source:cOndemned
    Published:1 Apr 2008
    6
    Medium

    CVE-2008-1606

    Last Modified: 6 Feb 2014

    Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a "..\" (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp.

    Source:Daniel Martin Gomez
    Published:1 Apr 2008
    6.8
    Medium

    CVE-2008-1605

    Last Modified: 10 Feb 2014

    The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.

    Source:shinnai
    Published:1 Apr 2008
    10
    Critical

    CVE-2008-1602

    Last Modified: 21 Apr 2015

    Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.

    Source:Metasploit
    Published:6 Apr 2008
    7.5
    High

    CVE-2008-1591

    Last Modified: 23 Apr 2026

    The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, as demonstrated by the CLIENT_IP HTTP header (HTTP_CLIENT_IP variable).

    Source:The:Paradox
    Published:31 Mar 2008
    7.5
    High

    CVE-2008-1565

    Last Modified: 10 Feb 2014

    Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.

    Source:0in
    Published:31 Mar 2008
    4.3
    Medium

    CVE-2008-1564

    Last Modified: 10 Feb 2014

    Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the filename.

    Source:teeed
    Published:31 Mar 2008
    4.3
    Medium

    CVE-2008-1563

    Last Modified: 17 Feb 2014

    The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Source:Peter Makrai
    Published:28 Mar 2008
    5
    Medium

    CVE-2008-1562

    Last Modified: 17 Feb 2014

    The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.

    Source:Peter Makrai
    Published:28 Mar 2008
    5
    Medium

    CVE-2008-1561

    Last Modified: 17 Feb 2014

    Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.

    Source:Peter Makrai
    Published:28 Mar 2008
    4.3
    Medium

    CVE-2008-1560

    Last Modified: 10 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_result.asp, and the (2) word1 and (3) word2 parameters to suggest_result.asp.

    Source:Linux_Drox
    Published:31 Mar 2008
    6.8
    Medium

    CVE-2008-1559

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Source:cO2
    Published:31 Mar 2008
    10
    Critical

    CVE-2008-1558

    Last Modified: 23 Nov 2016

    Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.

    Source:Guido Landi
    Published:31 Mar 2008
    5
    Medium

    CVE-2008-1557

    Last Modified: 16 Nov 2016

    BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which calls the phpinfo function.

    Source:DSecRG
    Published:31 Mar 2008
    4.3
    Medium

    CVE-2008-1556

    Last Modified: 16 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BolinOS 4.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) system/actionspages/_b/contentFiles/gBImageViewer.php, (2) ForEditor parameter to (b) system/actionspages/_b/contentFiles/gBselectorContents.php, (3) the PATH_INFO to (c) gBLoginPage.php and (d) gBPassword.php in system/actionspages/_b/contentFiles/, (4) formlogin parameter to system/actionspages/_b/contentFiles/gBLoginPage.php, and the (5) bolini_searchengine46Search parameter to (e) help/index.php.

    Source:DSecRG
    Published:31 Mar 2008
    6.8
    Medium

    CVE-2008-1555

    Last Modified: 16 Nov 2016

    Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _bFileToInclude parameter.

    Source:DSecRG
    Published:31 Mar 2008
    6.8
    Medium

    CVE-2008-1554

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a non-alphanumeric first character the localita parameter, which bypasses a protection mechanism.

    Source:girex
    Published:31 Mar 2008
    6.8
    Medium

    CVE-2008-1553

    Last Modified: 16 Nov 2016

    Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the to parameter.

    Source:girex
    Published:31 Mar 2008
    7.5
    High

    CVE-2008-1551

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:S@BUN
    Published:31 Mar 2008
    4.3
    Medium

    CVE-2008-1547

    Last Modified: 25 Mar 2014

    Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.

    Source:Martin Suess
    Published:21 Oct 2008
    4.3
    Medium

    CVE-2008-1541

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.

    Source:Zero X
    Published:28 Mar 2008
    7.5
    High

    CVE-2008-1540

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Cr@zy_King
    Published:28 Mar 2008
    7.5
    High

    CVE-2008-1539

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module.

    Source:Inphex
    Published:28 Mar 2008
    6.8
    Medium

    CVE-2008-1537

    Last Modified: 23 Nov 2016

    Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:DSecRG
    Published:28 Mar 2008
    7.5
    High

    CVE-2008-1535

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the op_id parameter in a view action to index.php.

    Source:Sniper456
    Published:28 Mar 2008
    7.5
    High

    CVE-2008-1534

    Last Modified: 23 Nov 2016

    Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php.

    Source:DSecRG
    Published:28 Mar 2008
    6.8
    Medium

    CVE-2008-1513

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.

    Source:InATeam
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1512

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.

    Source:bd0rk
    Published:25 Mar 2008
    9.8
    Critical

    CVE-2008-1511

    Last Modified: 7 Feb 2014

    Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:25 Mar 2008
    4.3
    Medium

    CVE-2008-1510

    Last Modified: 7 Feb 2014

    Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.

    Source:nnposter
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the query parameter.

    Source:cOndemned
    Published:25 Mar 2008