7.5
    High

    CVE-2008-1508

    Last Modified: 7 Feb 2014

    SQL injection vulnerability in EfesTech E-Kontör and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:RMx
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1507

    Last Modified: 16 Nov 2016

    PEEL, possibly 3.x and earlier, has (1) a default [email protected] account with password admin, and (2) a default [email protected] account with password cinema, which allows remote attackers to gain administrative access.

    Source:Charles Fol
    Published:25 Mar 2008
    5
    Medium

    CVE-2008-1506

    Last Modified: 16 Nov 2016

    PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Source:Charles Fol
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1505

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php.

    Source:Sniper456
    Published:25 Mar 2008
    4.3
    Medium

    CVE-2008-1504

    Last Modified: 7 Feb 2014

    Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven phpMyChat 0.14.5 allows remote attackers to inject arbitrary web script or HTML via the Lang parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:25 Mar 2008
    5
    Medium

    CVE-2008-1501

    Last Modified: 16 Nov 2016

    The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivatives allows remote attackers to cause a denial of service (daemon crash) via a malformed MODE command.

    Source:Chris Porter
    Published:25 Mar 2008
    4.3
    Medium

    CVE-2008-1500

    Last Modified: 7 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in TinyPortal 0.8.6 and 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Y433r
    Published:25 Mar 2008
    4.3
    Medium

    CVE-2008-1499

    Last Modified: 7 Feb 2014

    Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:Linux_Drox
    Published:25 Mar 2008
    9
    Critical

    CVE-2008-1498

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.

    Source:ryujin
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1496

    Last Modified: 16 Nov 2016

    Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in achat/historique_commandes.php and (c) the facture action in factures/facture_html.php.

    Source:Charles Fol
    Published:25 Mar 2008
    6.5
    Medium

    CVE-2008-1495

    Last Modified: 16 Nov 2016

    Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.

    Source:Charles Fol
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1493

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:KnocKout
    Published:25 Mar 2008
    7.5
    High

    CVE-2008-1492

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0.

    Source:0x90
    Published:25 Mar 2008
    10
    Critical

    CVE-2008-1491

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623.

    Source:Heretic2
    Published:25 Mar 2008
    6.8
    Medium

    CVE-2008-1489

    Last Modified: 23 Apr 2026

    Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.

    Source:j0rgan
    Published:25 Mar 2008
    6.8
    Medium

    CVE-2008-1488

    Last Modified: 10 Feb 2014

    Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename.

    Source:dannyp
    Published:24 Mar 2008
    3.5
    Low

    CVE-2008-1484

    Last Modified: 14 Nov 2016

    The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.

    Source:EpiBite
    Published:24 Mar 2008
    6.8
    Medium

    CVE-2008-1482

    Last Modified: 24 Nov 2016

    Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.

    Source:Luigi Auriemma
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1481

    Last Modified: 5 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the board parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:n3w7u
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1480

    Last Modified: 4 Oct 2017

    rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.

    Source:kingcope
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1479

    Last Modified: 5 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:24 Mar 2008
    5
    Medium

    CVE-2008-1478

    Last Modified: 23 Apr 2026

    Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode connection, then closing the original FTP connection. NOTE: some of these details are obtained from third party information.

    Source:0in
    Published:24 Mar 2008
    9.3
    Critical

    CVE-2008-1472

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

    Source:Metasploit
    Published:24 Mar 2008
    7.2
    High

    CVE-2008-1471

    Last Modified: 5 Feb 2014

    The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.

    Source:Tobias Klein
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1470

    Last Modified: 5 Feb 2014

    Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.

    Source:quentin.berdugo
    Published:24 Mar 2008
    6.8
    Medium

    CVE-2008-1467

    Last Modified: 23 Nov 2016

    CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "received URLs in the message window." NOTE: this issue has been disputed due to the user-assisted nature, since the URL must be selected and launched by the victim

    Source:Brian Fonfara
    Published:24 Mar 2008
    7.5
    High

    CVE-2008-1466

    Last Modified: 6 Feb 2014

    Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:24 Mar 2008
    9.3
    Critical

    CVE-2008-1465

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than CVE-2008-0562.

    Source:S@BUN
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1463

    Last Modified: 5 Feb 2014

    Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by SecureSphere, which triggers injection into the "corrective action" section of an alert page.

    Source:Berezniski
    Published:24 Mar 2008
    6.8
    Medium

    CVE-2008-1462

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle action.

    Source:Cr@zy_King
    Published:24 Mar 2008
    7.6
    High

    CVE-2008-1461

    Last Modified: 5 Feb 2014

    Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.

    Source:Sylvain THUAL
    Published:24 Mar 2008
    7.5
    High

    CVE-2008-1460

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:S@BUN
    Published:24 Mar 2008
    7.5
    High

    CVE-2008-1459

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:S@BUN
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1458

    Last Modified: 6 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also affected.

    Source:sasquatch
    Published:24 Mar 2008
    6.8
    Medium

    CVE-2008-1447

    Last Modified: 8 Sept 2017

    The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."

    Source:I)ruid
    Published:8 Jul 2008
    9
    Critical

    CVE-2008-1436

    Last Modified: 17 Feb 2014

    Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.

    Source:Cesar Cerrudo
    Published:21 Apr 2008
    7.5
    High

    CVE-2008-1430

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.

    Source:xcorpitx
    Published:20 Mar 2008
    7.5
    High

    CVE-2008-1427

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mailingid parameter in a mailing view action to index.php.

    Source:fataku
    Published:20 Mar 2008
    7.5
    High

    CVE-2008-1426

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter.

    Source:JosS
    Published:20 Mar 2008
    7.5
    High

    CVE-2008-1425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a kate action.

    Source:Easy Laster
    Published:20 Mar 2008
    6.8
    Medium

    CVE-2008-1416

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/.

    Source:RoMaNcYxHaCkEr
    Published:20 Mar 2008
    5
    Medium

    CVE-2008-1415

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter.

    Source:JosS
    Published:20 Mar 2008
    4.3
    Medium

    CVE-2008-1414

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4) smartlinks.php, and (5) todo.php, as demonstrated using a META tag.

    Source:JosS
    Published:20 Mar 2008
    4.3
    Medium

    CVE-2008-1413

    Last Modified: 5 Feb 2014

    Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:medprostuda.ru
    Published:20 Mar 2008
    5
    Medium

    CVE-2008-1411

    Last Modified: 23 Apr 2026

    The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:20 Mar 2008
    4.3
    Medium

    CVE-2008-1410

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.

    Source:Luigi Auriemma
    Published:20 Mar 2008
    7.5
    High

    CVE-2008-1409

    Last Modified: 23 Nov 2016

    Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.

    Source:GoLd_M
    Published:20 Mar 2008
    7.5
    High

    CVE-2008-1408

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a banner_out action.

    Source:irk4z
    Published:20 Mar 2008
    6.8
    Medium

    CVE-2008-1407

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

    Source:S@BUN
    Published:20 Mar 2008
    6.8
    Medium

    CVE-2008-1406

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.

    Source:S@BUN
    Published:20 Mar 2008