6.8
    Medium

    CVE-2008-1405

    Last Modified: 16 Nov 2016

    PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.

    Source:irk4z
    Published:20 Mar 2008
    6.8
    Medium

    CVE-2008-1404

    Last Modified: 16 Nov 2016

    SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter.

    Source:S@BUN
    Published:20 Mar 2008
    6.8
    Medium

    CVE-2008-1403

    Last Modified: 5 Feb 2014

    Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename.

    Source:Luigi Auriemma
    Published:20 Mar 2008
    7.1
    High

    CVE-2008-1402

    Last Modified: 16 Nov 2016

    MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory consumption) via a malformed request to the Net Inspector Server (niengine).

    Source:Luigi Auriemma
    Published:20 Mar 2008
    4.3
    Medium

    CVE-2008-1401

    Last Modified: 16 Nov 2016

    Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to execute arbitrary code via format string specifiers in the URI, which is recorded in a log file.

    Source:Luigi Auriemma
    Published:20 Mar 2008
    5
    Medium

    CVE-2008-1400

    Last Modified: 16 Nov 2016

    Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot slash) in the URI.

    Source:Luigi Auriemma
    Published:20 Mar 2008
    6.8
    Medium

    CVE-2008-1398

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

    Source:NTOS-Team
    Published:20 Mar 2008
    7.5
    High

    CVE-2008-1391

    Last Modified: 11 Feb 2014

    Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.

    Source:Maksymilian Arciemowicz
    Published:25 Mar 2008
    4.3
    Medium

    CVE-2008-1385

    Last Modified: 16 Feb 2014

    Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

    Source:Hanno Boeck
    Published:23 Apr 2008
    3.6
    Low

    CVE-2008-1371

    Last Modified: 24 Nov 2016

    Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:THE_MILLER
    Published:18 Mar 2008
    6.8
    Medium

    CVE-2008-1370

    Last Modified: 2 Feb 2014

    PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:THE_MILLER
    Published:18 Mar 2008
    6.4
    Medium

    CVE-2008-1365

    Last Modified: 5 Feb 2014

    Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.

    Source:Luigi Auriemma
    Published:17 Mar 2008
    6.5
    Medium

    CVE-2008-1358

    Last Modified: 5 Dec 2016

    Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY.

    Source:Metasploit
    Published:17 Mar 2008
    5.4
    Medium

    CVE-2008-1357

    Last Modified: 5 Feb 2014

    Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.

    Source:Luigi Auriemma
    Published:17 Mar 2008
    4.3
    Medium

    CVE-2008-1355

    Last Modified: 4 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in Jeebles Technology Jeebles Directory 2.9.60 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1354

    Last Modified: 5 Feb 2014

    SQL injection vulnerability in MyIssuesView.asp in Advanced Data Solutions Virtual Support Office-XP (VSO-XP) allows remote attackers to execute arbitrary SQL commands via the Issue_ID parameter.

    Source:The-0utl4w
    Published:17 Mar 2008
    4.3
    Medium

    CVE-2008-1353

    Last Modified: 17 Feb 2017

    zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

    Source:Milen Rangelov
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1351

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php.

    Source:S@BUN
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1350

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action.

    Source:TurkishWarriorr
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1349

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:S@BUN
    Published:17 Mar 2008
    4.3
    Medium

    CVE-2008-1348

    Last Modified: 5 Feb 2014

    Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php.

    Source:NetJackal
    Published:17 Mar 2008
    4.3
    Medium

    CVE-2008-1347

    Last Modified: 15 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the q parameter in an about action to the help system.

    Source:JosS
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1346

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action.

    Source:JosS
    Published:17 Mar 2008
    4.3
    Medium

    CVE-2008-1345

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and earlier allows remote attackers to inject arbitrary web script or HTML via the day parameter in a dayview action.

    Source:JosS
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1344

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter to ajaxp_backend.php.

    Source:JosS
    Published:17 Mar 2008
    4.9
    Medium

    CVE-2008-1343

    Last Modified: 17 Nov 2016

    Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in SCO UnixWare 7.1.4 allows local users to gain privileges via unknown vectors.

    Source:qaaz
    Published:17 Mar 2008
    7.5
    High

    CVE-2008-1336

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in Koobi CMS 4.2.3 through 4.3.0 allows remote attackers to execute arbitrary SQL commands via the categ parameter in a links action to index.php, a different vector than CVE-2008-1122.

    Source:JosS
    Published:13 Mar 2008
    10
    Critical

    CVE-2008-1331

    Last Modified: 23 Apr 2026

    cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.

    Source:DSecRG
    Published:2 Apr 2008
    7.5
    High

    CVE-2008-1327

    Last Modified: 3 Feb 2014

    Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:13 Mar 2008
    4.3
    Medium

    CVE-2008-1326

    Last Modified: 3 Feb 2014

    Cross-site scripting (XSS) vulnerability in search.php in Gallarific allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:13 Mar 2008
    7.5
    High

    CVE-2008-1325

    Last Modified: 4 Feb 2014

    Multiple directory traversal vulnerabilities in index.php in Uberghey CMS 0.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page_id and (2) language parameters. NOTE: this might be the same issue as CVE-2008-1324.

    Source:muuratsalo
    Published:13 Mar 2008
    7.5
    High

    CVE-2008-1324

    Last Modified: 4 Feb 2014

    Multiple directory traversal vulnerabilities in index.php in Travelsized CMS 0.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page_id and (2) language parameters. NOTE: this might be the same issue as CVE-2008-1325.

    Source:muuratsalo
    Published:13 Mar 2008
    7.8
    High

    CVE-2008-1322

    Last Modified: 23 Apr 2026

    The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a denial of service (CPU consumption) or overwrite arbitrary files via a query string that specifies the -b option, probably due to an argument injection vulnerability.

    Source:Luigi Auriemma
    Published:13 Mar 2008
    5
    Medium

    CVE-2008-1321

    Last Modified: 23 Apr 2026

    The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands.

    Source:Luigi Auriemma
    Published:13 Mar 2008
    10
    Critical

    CVE-2008-1320

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary code or cause a denial of service (crash) via (1) a long request to FxIAList on TCP port 6162, or (2) an SNMP request with a long community string to FxAgent on UDP port 6161.

    Source:Luigi Auriemma
    Published:13 Mar 2008
    9.3
    Critical

    CVE-2008-1319

    Last Modified: 14 Jul 2017

    Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.

    Source:Luigi Auriemma
    Published:13 Mar 2008
    6.8
    Medium

    CVE-2008-1316

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:13 Mar 2008
    7.5
    High

    CVE-2008-1315

    Last Modified: 3 Feb 2014

    SQL injection vulnerability in the ZClassifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter to modules.php.

    Source:Lovebug
    Published:13 Mar 2008
    7.5
    High

    CVE-2008-1314

    Last Modified: 31 Jan 2014

    SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to modules.php.

    Source:TurkishWarriorr
    Published:12 Mar 2008
    7.5
    High

    CVE-2008-1313

    Last Modified: 23 Nov 2016

    Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) post_id, (2) post_category_id, (3) post_year_month, and (4) static_page_id parameters; and unspecified other vectors.

    Source:MhZ91
    Published:12 Mar 2008
    5
    Medium

    CVE-2008-1311

    Last Modified: 23 Apr 2026

    The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of service (daemon hang) by uploading a file named (1) '|' (pipe), (2) '"' (quotation mark), or (3) "<>" (less than, greater than); or (4) a file with a long name. NOTE: the issue for vector 4 might exist because of an incomplete fix for CVE-2008-1312.

    Source:Jeremy Brown
    Published:12 Mar 2008
    9.3
    Critical

    CVE-2008-1309

    Last Modified: 23 Apr 2026

    The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.

    Source:Elazar
    Published:12 Mar 2008
    7.5
    High

    CVE-2008-1308

    Last Modified: 3 Feb 2014

    SQL injection vulnerability in the Sudirman Angriawan NukeC30 3.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action to modules.php.

    Source:Houssamix
    Published:12 Mar 2008
    10
    Critical

    CVE-2008-1307

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method.

    Source:void
    Published:12 Mar 2008
    7.5
    High

    CVE-2008-1305

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:t0pP8uZz
    Published:12 Mar 2008
    4.3
    Medium

    CVE-2008-1304

    Last Modified: 4 May 2017

    Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) inviteemail parameter in an invite action to wp-admin/users.php and the (2) to parameter in a sent action to wp-admin/invites.php.

    Source:Doz
    Published:7 Mar 2008
    5
    Medium

    CVE-2008-1303

    Last Modified: 5 Feb 2014

    The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a missing parameter to the (1) dm-FaultFile, (2) dm-LazyCheck, (3) dm-ResolvedFile, (4) dm-OpenFile, (5) crypto, and possibly unspecified other commands, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:12 Mar 2008
    4
    Medium

    CVE-2008-1301

    Last Modified: 3 Feb 2014

    Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.

    Source:nnposter
    Published:12 Mar 2008
    4.3
    Medium

    CVE-2008-1300

    Last Modified: 3 Feb 2014

    Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the filePath.0 parameter in a save action, a different vector than CVE-2008-1045.

    Source:nnposter
    Published:12 Mar 2008
    7.5
    High

    CVE-2008-1298

    Last Modified: 3 Feb 2014

    SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cat parameter in a viewcat action to modules.php.

    Source:Lovebug
    Published:12 Mar 2008