7.5
    High

    CVE-2008-1297

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.

    Source:Don
    Published:12 Mar 2008
    4.3
    Medium

    CVE-2008-1296

    Last Modified: 3 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote attackers to inject arbitrary web script or HTML via the file parameter to (1) watermark.php and (2) catalog_watermark.php in core/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:12 Mar 2008
    6.8
    Medium

    CVE-2008-1295

    Last Modified: 23 Nov 2016

    SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter.

    Source:Charles Fol
    Published:12 Mar 2008
    7.5
    High

    CVE-2008-1289

    Last Modified: 6 Feb 2014

    Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.

    Source:Mu Security research
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-1283

    Last Modified: 3 Feb 2014

    Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page.

    Source:NetJackal
    Published:11 Mar 2008
    5
    Medium

    CVE-2008-1278

    Last Modified: 3 Feb 2014

    The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of service (crash) via an invalid Accept-Charset header, which triggers a NULL pointer dereference. NOTE: the service is automatically restarted.

    Source:Luigi Auriemma
    Published:10 Mar 2008
    9
    Critical

    CVE-2008-1277

    Last Modified: 5 Feb 2014

    The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of service (crash) via (1) SEARCH and (2) APPEND commands without required arguments, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:10 Mar 2008
    9
    Critical

    CVE-2008-1276

    Last Modified: 15 Nov 2016

    Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execute arbitrary code via long arguments to the (1) FETCH, (2) EXAMINE, and (3) UNSUBSCRIBE commands.

    Source:haluznik
    Published:10 Mar 2008
    7.8
    High

    CVE-2008-1275

    Last Modified: 15 Nov 2016

    Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edition 3.x and earlier allow remote attackers to cause a denial of service (crash) via crafted (1) EXPN or (2) VRFY commands.

    Source:ryujin
    Published:10 Mar 2008
    4.3
    Medium

    CVE-2008-1273

    Last Modified: 3 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) popup.php, (2) test/dir2.php, (3) admin/upload.php, and (4) dirxml.php in upload/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ZoRLu
    Published:10 Mar 2008
    7.5
    High

    CVE-2008-1272

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showad.php and the (2) ad parameter to pfriendly.php.

    Source:xcorpitx
    Published:10 Mar 2008
    5
    Medium

    CVE-2008-1270

    Last Modified: 4 Feb 2014

    mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

    Source:julien.cayzac
    Published:10 Mar 2008
    10
    Critical

    CVE-2008-1262

    Last Modified: 2 Feb 2014

    The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.

    Source:Francis Lacoste-Cordeau
    Published:10 Mar 2008
    10
    Critical

    CVE-2008-1247

    Last Modified: 24 Jan 2017

    The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers to perform arbitrary administrative actions via a direct request to (1) Advanced.tri, (2) AdvRoute.tri, (3) Basic.tri, (4) ctlog.tri, (5) ddns.tri, (6) dmz.tri, (7) factdefa.tri, (8) filter.tri, (9) fw.tri, (10) manage.tri, (11) ping.tri, (12) PortRange.tri, (13) ptrigger.tri, (14) qos.tri, (15) rstatus.tri, (16) tracert.tri, (17) vpn.tri, (18) WanMac.tri, (19) WBasic.tri, or (20) WFilter.tri. NOTE: the Security.tri vector is already covered by CVE-2006-5202.

    Source:meathive
    Published:10 Mar 2008
    7.8
    High

    CVE-2008-1245

    Last Modified: 8 Sept 2017

    cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a denial of service (control center outage) via an HTTP request with invalid POST data and a "Connection: Keep-Alive" header.

    Source:noensr
    Published:10 Mar 2008
    10
    Critical

    CVE-2008-1244

    Last Modified: 8 Sept 2017

    cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.

    Source:noensr
    Published:10 Mar 2008
    10
    Critical

    CVE-2008-1242

    Last Modified: 8 Sept 2017

    The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user, a different vulnerability than CVE-2005-3802.

    Source:noensr
    Published:10 Mar 2008
    4.3
    Medium

    CVE-2008-1232

    Last Modified: 10 Mar 2014

    Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

    Source:Konstantin Kolinko
    Published:1 Aug 2008
    9.3
    Critical

    CVE-2008-1231

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.

    Source:BugSec LTD
    Published:10 Mar 2008
    9.3
    Critical

    CVE-2008-1230

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page."

    Source:BugSec LTD
    Published:10 Mar 2008
    4.3
    Medium

    CVE-2008-1229

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via the editor parameter, a different vector than CVE-2007-5120.b.

    Source:BugSec LTD
    Published:10 Mar 2008
    4.3
    Medium

    CVE-2008-1228

    Last Modified: 2 Feb 2014

    Cross-site scripting (XSS) vulnerability in admin.php in MG2 (formerly Minigal) allows remote attackers to inject arbitrary web script or HTML via the list parameter in an import action.

    Source:Jose Carlos Norte
    Published:10 Mar 2008
    4.3
    Medium

    CVE-2008-1225

    Last Modified: 2 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated users to inject arbitrary web script or HTML via a (1) mail message or (2) discussion board message. NOTE: this might overlap CVE-2005-1076.

    Source:Lupton
    Published:10 Mar 2008
    5
    Medium

    CVE-2008-1221

    Last Modified: 2 Feb 2014

    Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command.

    Source:Luigi Auriemma
    Published:10 Mar 2008
    7.5
    High

    CVE-2008-1220

    Last Modified: 3 Feb 2014

    SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:meloulisi
    Published:10 Mar 2008
    7.5
    High

    CVE-2008-1219

    Last Modified: 2 Feb 2014

    SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the kid parameter in a hadisgoster action to modules.php.

    Source:r080cy90r
    Published:10 Mar 2008
    6.8
    Medium

    CVE-2008-1218

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.

    Source:kingcope
    Published:9 Mar 2008
    4.6
    Medium

    CVE-2008-1215

    Last Modified: 2 Feb 2014

    Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.

    Source:sipherr
    Published:9 Mar 2008
    4.3
    Medium

    CVE-2008-1208

    Last Modified: 2 Feb 2014

    Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Source:Henri Lindberg
    Published:8 Mar 2008
    9.3
    Critical

    CVE-2008-1193

    Last Modified: 5 Feb 2014

    Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application.

    Source:Chris Evans
    Published:6 Mar 2008
    5
    Medium

    CVE-2008-1181

    Last Modified: 31 Jan 2014

    Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message.

    Source:Richard Brain
    Published:6 Mar 2008
    4.3
    Medium

    CVE-2008-1180

    Last Modified: 31 Jan 2014

    Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attackers to inject arbitrary web script or HTML via the delivery_mode parameter.

    Source:Richard Brain
    Published:6 Mar 2008
    4.3
    Medium

    CVE-2008-1178

    Last Modified: 31 Jan 2014

    Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.

    Source:JosS
    Published:6 Mar 2008
    7.5
    High

    CVE-2008-1177

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:6 Mar 2008
    2.6
    Low

    CVE-2008-1176

    Last Modified: 14 Nov 2016

    Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to inject arbitrary web script or HTML via the sideblock4 parameter.

    Source:Khashayar Fereidani
    Published:6 Mar 2008
    4.3
    Medium

    CVE-2008-1174

    Last Modified: 31 Jan 2014

    Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Source:William Hicks
    Published:6 Mar 2008
    4.3
    Medium

    CVE-2008-1173

    Last Modified: 31 Jan 2014

    Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:Dominus
    Published:6 Mar 2008
    6.8
    Medium

    CVE-2008-1170

    Last Modified: 31 Jan 2014

    Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the page parameter to (1) minimal/wiki.php and (2) simplest/wiki.php.

    Source:muuratsalo
    Published:5 Mar 2008
    7.8
    High

    CVE-2008-1169

    Last Modified: 28 Jan 2014

    Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot forward slash) in the GET command.

    Source:Luigi Auriemma
    Published:5 Mar 2008
    7.5
    High

    CVE-2008-1164

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via the mod_project_id parameter in a project_detail action.

    Source:Cr@zy_King
    Published:5 Mar 2008
    7.5
    High

    CVE-2008-1163

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action.

    Source:SoSo H H
    Published:5 Mar 2008
    7.5
    High

    CVE-2008-1162

    Last Modified: 15 Nov 2016

    SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.

    Source:Aria-Security Team
    Published:5 Mar 2008
    9.8
    Critical

    CVE-2008-1160

    Last Modified: 5 Dec 2016

    ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

    Source:Pranav Joshi
    Published:25 Mar 2008
    5
    Medium

    CVE-2008-1145

    Last Modified: 21 Dec 2016

    Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.

    Source:DSecRG
    Published:3 Mar 2008
    4.9
    Medium

    CVE-2008-1141

    Last Modified: 23 Apr 2026

    Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests to \\.\DLKPFSD_Device that allocate "link list structures."

    Source:mu-b
    Published:4 Mar 2008
    7.2
    High

    CVE-2008-1140

    Last Modified: 23 Apr 2026

    DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Control that overwrites a data structure associated with a mounted pseudo-filesystem, aka the "ring0 SYSTEM" vulnerability.

    Source:mu-b
    Published:4 Mar 2008
    7.2
    High

    CVE-2008-1139

    Last Modified: 23 Apr 2026

    DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, aka the "ring0 link list zero SYSTEM" vulnerability.

    Source:mu-b
    Published:4 Mar 2008
    4.9
    Medium

    CVE-2008-1138

    Last Modified: 23 Apr 2026

    DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a certain ZERO_MEM DLMFENC_IOCTL request to \\.\DLKPFSD_Device, aka the "ring0 link list zero" vulnerability.

    Source:mu-b
    Published:4 Mar 2008
    7.5
    High

    CVE-2008-1137

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:S@BUN
    Published:4 Mar 2008
    9.3
    Critical

    CVE-2008-1136

    Last Modified: 17 Jan 2014

    The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attackers to execute arbitrary commands via shell metacharacters in a certain string to TCP port 5679.

    Source:Alfredo Ortega
    Published:4 Mar 2008