10
    Critical

    CVE-2008-0960

    Last Modified: 23 Apr 2026

    SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

    Source:Maurizio Agazzini
    Published:9 Jun 2008
    9.3
    Critical

    CVE-2008-0955

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value.

    Source:Metasploit
    Published:29 May 2008
    10
    Critical

    CVE-2008-0953

    Last Modified: 25 Feb 2014

    The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.

    Source:Dennis Rand
    Published:4 Jun 2008
    9.3
    Critical

    CVE-2008-0952

    Last Modified: 25 Feb 2014

    The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.

    Source:Dennis Rand
    Published:4 Jun 2008
    5
    Medium

    CVE-2008-0944

    Last Modified: 18 Dec 2016

    Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero.

    Source:Luigi Auriemma
    Published:25 Feb 2008
    7.5
    High

    CVE-2008-0943

    Last Modified: 30 Jan 2014

    Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.

    Source:Arsalan Emamjomehkashan
    Published:25 Feb 2008
    7.5
    High

    CVE-2008-0942

    Last Modified: 30 Jan 2014

    SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter.

    Source:Arsalan Emamjomehkashan
    Published:25 Feb 2008
    7.5
    High

    CVE-2008-0939

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information.

    Source:S@BUN
    Published:25 Feb 2008
    6.8
    Medium

    CVE-2008-0937

    Last Modified: 30 Jan 2014

    SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.

    Source:S@BUN
    Published:25 Feb 2008
    7.5
    High

    CVE-2008-0936

    Last Modified: 30 Jan 2014

    SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

    Source:S@BUN
    Published:25 Feb 2008
    10
    Critical

    CVE-2008-0935

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.

    Source:Metasploit
    Published:25 Feb 2008
    7.5
    High

    CVE-2008-0934

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action.

    Source:DamaR
    Published:25 Feb 2008
    5
    Medium

    CVE-2008-0927

    Last Modified: 23 Apr 2026

    dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.

    Source:Nicob
    Published:14 Apr 2008
    7.5
    High

    CVE-2008-0926

    Last Modified: 10 Feb 2014

    The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

    Source:Nicholas Gregorie
    Published:28 Mar 2008
    7.5
    High

    CVE-2008-0922

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.

    Source:Mehmet Ince
    Published:22 Feb 2008
    7.5
    High

    CVE-2008-0921

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Cr@zy_King
    Published:22 Feb 2008
    6.5
    Medium

    CVE-2008-0920

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.

    Source:Marcin Kopec
    Published:22 Feb 2008
    4.3
    Medium

    CVE-2008-0919

    Last Modified: 14 Nov 2016

    Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

    Source:Marcin Kopec
    Published:22 Feb 2008
    7.5
    High

    CVE-2008-0918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ka0x
    Published:22 Feb 2008
    7.5
    High

    CVE-2008-0916

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.

    Source:S@BUN
    Published:22 Feb 2008
    10
    Critical

    CVE-2008-0912

    Last Modified: 5 Feb 2014

    Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:22 Feb 2008
    6.5
    Medium

    CVE-2008-0911

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.

    Source:t0pP8uZz
    Published:22 Feb 2008
    7.5
    High

    CVE-2008-0907

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:Crackers_Child
    Published:22 Feb 2008
    7.5
    High

    CVE-2008-0906

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.

    Source:DamaR
    Published:22 Feb 2008
    5
    Medium

    CVE-2008-0905

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:GoLd_M
    Published:22 Feb 2008
    7.5
    High

    CVE-2008-0881

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.

    Source:Mehmet Ince
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0880

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Source:Mehmet Ince
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0879

    Last Modified: 28 Jan 2014

    SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.

    Source:S@BUN
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0878

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

    Source:S@BUN
    Published:21 Feb 2008
    4.3
    Medium

    CVE-2008-0877

    Last Modified: 28 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php; the frontend, theme, and (6) language parameters to (b) ajax_request.php; the jz_path parameter to (c) slim.php; the frontend, theme, and jz_path parameters to (d) popup.php; the (13) PATH_INFO to index.php and (e) slim.php; and the (14) query parameter in a playlistedit action and (15) siteNewsData parameter in a sitenews action to (f) popup.php.

    Source:Alexandr Polyakov
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0874

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

    Source:S@BUN
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0873

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action.

    Source:S@BUN
    Published:21 Feb 2008
    4.3
    Medium

    CVE-2008-0872

    Last Modified: 28 Jan 2014

    Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.

    Source:Juan Pablo Lopez Yacubian
    Published:21 Feb 2008
    6.8
    Medium

    CVE-2008-0871

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.

    Source:Metasploit
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0857

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList page.

    Source:NBBN
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0856

    Last Modified: 21 Dec 2016

    Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Khashayar Fereidani
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0855

    Last Modified: 28 Jan 2014

    SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Source:S@BUN
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0854

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.

    Source:S@BUN
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0853

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so, it should not be included in CVE.

    Source:S@BUN
    Published:21 Feb 2008
    5
    Medium

    CVE-2008-0852

    Last Modified: 28 Jun 2018

    freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:21 Feb 2008
    4.3
    Medium

    CVE-2008-0851

    Last Modified: 26 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.

    Source:Alexandr Polyakov
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0850

    Last Modified: 26 Jan 2014

    Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.

    Source:Alexandr Polyakov
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0847

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

    Source:S@BUN
    Published:21 Feb 2008
    7.5
    High

    CVE-2008-0846

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.

    Source:S@BUN
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0845

    Last Modified: 28 Jan 2014

    SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the person parameter.

    Source:S@BUN
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0844

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Source:S@BUN
    Published:20 Feb 2008
    6.4
    Medium

    CVE-2008-0843

    Last Modified: 23 Apr 2026

    StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.

    Source:Phenom
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0842

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:S@BUN
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0841

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:S@BUN
    Published:20 Feb 2008
    4.4
    Medium

    CVE-2008-0840

    Last Modified: 9 Nov 2016

    Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the username parameter.

    Source:muuratsalo
    Published:20 Feb 2008