7.5
    High

    CVE-2008-0839

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ka0x
    Published:20 Feb 2008
    4.3
    Medium

    CVE-2008-0838

    Last Modified: 26 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) error and (2) go parameters to the login page.

    Source:Leon Juranic
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0835

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the area parameter.

    Source:JosS
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0833

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:S@BUN
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0832

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action.

    Source:Don
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0831

    Last Modified: 5 Dec 2016

    Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) user_id or (2) category_id parameter. NOTE: this might overlap CVE-2008-0754.

    Source:S@BUN
    Published:20 Feb 2008
    7.5
    High

    CVE-2008-0830

    Last Modified: 2 Nov 2016

    The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: URI, a different vulnerability than CVE-2008-0043.

    Source:David Wharton
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0829

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task.

    Source:S@BUN
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0827

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:S@BUN
    Published:19 Feb 2008
    3.6
    Low

    CVE-2008-0822

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a .. (dot dot) in the page parameter.

    Source:muuratsalo
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0821

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attackers to execute arbitrary SQL commands via the questid parameter in an expand_question action.

    Source:Xar
    Published:19 Feb 2008
    3.6
    Low

    CVE-2008-0819

    Last Modified: 26 Jan 2014

    Directory traversal vulnerability in index.php in PlutoStatus Locator 1.0 pre alpha allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:muuratsalo
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0818

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie to (1) comment.php, (2) index.php, and (3) show.php.

    Source:MhZ91
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0817

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.

    Source:S@BUN
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0816

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in the com_sg component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the pid parameter in an order task.

    Source:S@BUN
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0815

    Last Modified: 23 Jan 2014

    SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task.

    Source:S@BUN
    Published:19 Feb 2008
    6.4
    Medium

    CVE-2008-0814

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the upload_filename parameter.

    Source:GoLd_M
    Published:19 Feb 2008
    5
    Medium

    CVE-2008-0813

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.

    Source:GoLd_M
    Published:19 Feb 2008
    6.4
    Medium

    CVE-2008-0812

    Last Modified: 26 Jan 2014

    Directory traversal vulnerability in DMS/index.php in BanPro DMS 1.0 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the action parameter.

    Source:muuratsalo
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0811

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1) the kid parameter to (a) mod/dl.php or (b) mod/links.php, and (2) the query parameter to search.php.

    Source:NTOS-Team
    Published:19 Feb 2008
    7.5
    High

    CVE-2008-0810

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:S@BUN
    Published:19 Feb 2008
    9.3
    Critical

    CVE-2008-0805

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures.

    Source:ZoRLu
    Published:18 Feb 2008
    6.8
    Medium

    CVE-2008-0804

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to execute arbitrary PHP code via a URL in the name parameter.

    Source:Crackers_Child
    Published:18 Feb 2008
    7.5
    High

    CVE-2008-0803

    Last Modified: 14 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the sys_conf[path][real] parameter to (1) modules\class\Table.php; (2) db_admins.php, (3) db_alert.php, (4) db_double.php, (5) db_games.php, (6) db_matches.php, (7) db_match_teams.php, (8) db_news.php, (9) db_platform.php, (10) db_players.php, (11) db_server_group.php, (12) db_server_ip.php, (13) db_teams.php, (14) db_team_players.php, (15) db_tournaments.php, (16) db_tournament_teams.php, and (17) db_trees.php in modules\class\db\; and (18) Match.php, (19) MatchTeam.php, (20) Rule.php, (21) RuleBuilder.php, (22) RulePool.php, (23) RuleSingle.php, (24) RuleTree.php, (25) Tournament.php, (26) TournamentTeam.php, (27) Tree.php, and (28) TreeSingle.php in modules\class\tournament\. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

    Source:MhZ91
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0802

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the albumnum parameter in a contact action.

    Source:Inphex
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0801

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the iid parameter in a view action, and possibly (2) the userid parameter.

    Source:S@BUN
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0800

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

    Source:S@BUN
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0799

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.

    Source:S@BUN
    Published:15 Feb 2008
    4.3
    Medium

    CVE-2008-0798

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ta parameter to artmedic_index.php, reached through index.php; and the (2) date parameter to artmedic_print.php.

    Source:muuratsalo
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0796

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

    Source:Khashayar Fereidani
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0795

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.

    Source:S@BUN
    Published:15 Feb 2008
    6.4
    Medium

    CVE-2008-0794

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:GoLd_M
    Published:15 Feb 2008
    5
    Medium

    CVE-2008-0790

    Last Modified: 23 Jan 2014

    Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:Luigi Auriemma
    Published:15 Feb 2008
    6.5
    Medium

    CVE-2008-0787

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.

    Source:F
    Published:15 Feb 2008
    7.5
    High

    CVE-2008-0785

    Last Modified: 23 Jan 2014

    Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.

    Source:aScii
    Published:14 Feb 2008
    4.3
    Medium

    CVE-2008-0783

    Last Modified: 23 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.

    Source:aScii
    Published:14 Feb 2008
    5
    Medium

    CVE-2008-0782

    Last Modified: 22 Nov 2017

    Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can be leveraged for PHP code execution via the quicklinks parameter.

    Source:nonroot
    Published:20 Jan 2008
    7.5
    High

    CVE-2008-0778

    Last Modified: 14 Nov 2016

    Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix methods.

    Source:laurent gaffié
    Published:14 Feb 2008
    7.5
    High

    CVE-2008-0776

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Source:SoSo H H
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0773

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CheebaHawk215
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0772

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.

    Source:S@BUN
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0770

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter.

    Source:RST/GHC
    Published:13 Feb 2008
    5
    Medium

    CVE-2008-0767

    Last Modified: 23 Jan 2014

    ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read.

    Source:Luigi Auriemma
    Published:13 Feb 2008
    10
    Critical

    CVE-2008-0764

    Last Modified: 22 Jan 2014

    Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114.

    Source:Luigi Auriemma
    Published:13 Feb 2008
    10
    Critical

    CVE-2008-0763

    Last Modified: 22 Jan 2014

    Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114.

    Source:Luigi Auriemma
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0761

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action.

    Source:S@BUN
    Published:13 Feb 2008
    5
    Medium

    CVE-2008-0760

    Last Modified: 23 Jan 2014

    Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483.

    Source:Luigi Auriemma
    Published:13 Feb 2008
    5
    Medium

    CVE-2008-0756

    Last Modified: 23 Jan 2014

    The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a "Send queue state" LPD command 3 or (2) a "Send queue state" LPD command 4.

    Source:Luigi Auriemma
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0755

    Last Modified: 28 Jan 2014

    Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute arbitrary code via format string specifiers in the queue name in a request.

    Source:Luigi Auriemma
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0754

    Last Modified: 5 Dec 2016

    Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action.

    Source:S@BUN
    Published:13 Feb 2008