7.5
    High

    CVE-2008-0753

    Last Modified: 22 Jan 2014

    SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.

    Source:Pouya_Server
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0752

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.

    Source:S@BUN
    Published:13 Feb 2008
    4.3
    Medium

    CVE-2008-0751

    Last Modified: 31 Oct 2016

    Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/.

    Source:Alexander Brachmann
    Published:13 Feb 2008
    4.3
    Medium

    CVE-2008-0749

    Last Modified: 22 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action.

    Source:Psiczn
    Published:13 Feb 2008
    10
    Critical

    CVE-2008-0748

    Last Modified: 10 Nov 2016

    Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party information.

    Source:Trancek
    Published:13 Feb 2008
    9.3
    Critical

    CVE-2008-0747

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487.

    Source:laurent gaffié
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0746

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:S@BUN
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0745

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:Houssamix
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0744

    Last Modified: 20 Jan 2014

    SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page.

    Source:milad_sa2007
    Published:13 Feb 2008
    10
    Critical

    CVE-2008-0743

    Last Modified: 22 Jan 2014

    PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hlp parameter.

    Source:Cr@zy_King
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0742

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/; and (2) the page parameter to (g) pnadmin/index.php. NOTE: vector 2 is only exploitable by administrators.

    Source:DSecRG
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0739

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter.

    Source:BugReport.IR
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0738

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:BugReport.IR
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0737

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter.

    Source:BugReport.IR
    Published:13 Feb 2008
    5
    Medium

    CVE-2008-0736

    Last Modified: 23 Apr 2026

    admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.

    Source:BugReport.IR
    Published:13 Feb 2008
    10
    Critical

    CVE-2008-0735

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.

    Source:DNX
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0734

    Last Modified: 10 Nov 2016

    SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the cuid cookie parameter to admin.php.

    Source:The:Paradox
    Published:13 Feb 2008
    7.5
    High

    CVE-2008-0733

    Last Modified: 23 Jan 2014

    SQL injection vulnerability in index.php in CS Team Counter Strike Portals allows remote attackers to execute arbitrary SQL commands via the id parameter, as demonstrated using the downloads page.

    Source:S@BUN
    Published:13 Feb 2008
    7.1
    High

    CVE-2008-0729

    Last Modified: 2 Nov 2016

    Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a related issue to CVE-2006-3677. NOTE: some of these details are obtained from third party information.

    Source:fuzion
    Published:12 Feb 2008
    5
    Medium

    CVE-2008-0724

    Last Modified: 23 Apr 2026

    The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts.

    Source:sub
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0723

    Last Modified: 21 Jan 2014

    Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.

    Source:SkyOut
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0722

    Last Modified: 21 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter in a pagetool_search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Phanter-Root
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0721

    Last Modified: 10 Nov 2016

    SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands via the gid parameter.

    Source:S@BUN
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0719

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.

    Source:it's my
    Published:12 Feb 2008
    6.8
    Medium

    CVE-2008-0714

    Last Modified: 10 Nov 2016

    SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lost_password_go action.

    Source:Moubik
    Published:12 Feb 2008
    5
    Medium

    CVE-2008-0703

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php.

    Source:muuratsalo
    Published:12 Feb 2008
    9.3
    Critical

    CVE-2008-0702

    Last Modified: 9 Nov 2016

    Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) USER or (2) PASS command, different vectors than CVE-2004-1641.

    Source:securfrog
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0700

    Last Modified: 21 Jan 2014

    Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Psiczn
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0695

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action.

    Source:S@BUN
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0692

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Source:QTRinux
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0691

    Last Modified: 21 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wp_footnotes_current_settings[priority], (2) wp_footnotes_current_settings[style_rules], (3) wp_footnotes_current_settings[pre_footnotes], and (4) wp_footnotes_current_settings[post_footnotes] parameters.

    Source:NBBN
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0690

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action.

    Source:GoLd_M
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0689

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_category action.

    Source:SoSo H H
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0688

    Last Modified: 21 Jan 2014

    Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.

    Source:Crackers_Child
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0686

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:S@BUN
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0685

    Last Modified: 21 Jan 2014

    SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

    Source:Crackers_Child
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0684

    Last Modified: 21 Jan 2014

    Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter.

    Source:Crackers_Child
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0683

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.

    Source:S@BUN
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0682

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:S@BUN
    Published:12 Feb 2008
    6.8
    Medium

    CVE-2008-0681

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action.

    Source:the redc0ders
    Published:12 Feb 2008
    7.8
    High

    CVE-2008-0680

    Last Modified: 23 Apr 2026

    SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.

    Source:ShadOS
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0679

    Last Modified: 14 Nov 2016

    Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:Khashayar Fereidani
    Published:12 Feb 2008
    6.8
    Medium

    CVE-2008-0678

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action.

    Source:Khashayar Fereidani
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0677

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action.

    Source:Khashayar Fereidani
    Published:12 Feb 2008
    4.3
    Medium

    CVE-2008-0676

    Last Modified: 9 Nov 2016

    Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

    Source:Khashayar Fereidani
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0675

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter.

    Source:sub
    Published:12 Feb 2008
    10
    Critical

    CVE-2008-0671

    Last Modified: 18 Dec 2016

    Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code via a long chat message, related to conversion from LF to CRLF.

    Source:Luigi Auriemma
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0670

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action.

    Source:xcorpitx
    Published:12 Feb 2008
    6.8
    Medium

    CVE-2008-0661

    Last Modified: 30 Mar 2017

    Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI. NOTE: this might be the same issue as CVE-2004-1569.

    Source:securfrog
    Published:8 Feb 2008
    9.3
    Critical

    CVE-2008-0660

    Last Modified: 9 Nov 2016

    Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.

    Source:Elazar
    Published:8 Feb 2008