10
    Critical

    CVE-2008-0659

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.

    Source:Elazar
    Published:8 Feb 2008
    7.5
    High

    CVE-2008-0653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.

    Source:Crackers_Child
    Published:7 Feb 2008
    7.5
    High

    CVE-2008-0652

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.

    Source:S@BUN
    Published:7 Feb 2008
    7.5
    High

    CVE-2008-0651

    Last Modified: 21 Jan 2014

    SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Psiczn
    Published:7 Feb 2008
    7.5
    High

    CVE-2008-0650

    Last Modified: 21 Jan 2014

    SQL injection vulnerability in login.php in Simple OS CMS 0.1c beta allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Psiczn
    Published:7 Feb 2008
    7.5
    High

    CVE-2008-0649

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.

    Source:you_kn0w
    Published:7 Feb 2008
    6.8
    Medium

    CVE-2008-0648

    Last Modified: 14 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4) Filter.php, (5) Form.php, (6) FormManager.php, (7) LoginManager.php, and (8) Filters/SingleFilter.php in scripts/classes/.

    Source:Trancek
    Published:7 Feb 2008
    10
    Critical

    CVE-2008-0647

    Last Modified: 14 Nov 2016

    Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.

    Source:luoluo
    Published:7 Feb 2008
    7.5
    High

    CVE-2008-0645

    Last Modified: 14 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) config/conf-activation.php, (2) menu/item.php, and (3) modules/conf_modules.php in admin/system/; and (4) system/login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Psiczn
    Published:7 Feb 2008
    5
    Medium

    CVE-2008-0636

    Last Modified: 22 Jan 2014

    Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information.

    Source:Brook Powers
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0634

    Last Modified: 23 Apr 2026

    Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.

    Source:plan-s
    Published:6 Feb 2008
    6
    Medium

    CVE-2008-0633

    Last Modified: 21 Jan 2014

    Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to cause a denial of service (exception) via a user name with a large number of quotes, which triggers the overflow during escaping.

    Source:L4teral
    Published:6 Feb 2008
    9.3
    Critical

    CVE-2008-0632

    Last Modified: 9 Nov 2016

    Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root directory.

    Source:Omni
    Published:6 Feb 2008
    4.3
    Medium

    CVE-2008-0631

    Last Modified: 23 Apr 2026

    Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddStringToFile method.

    Source:darkl0rd
    Published:6 Feb 2008
    4.3
    Medium

    CVE-2008-0625

    Last Modified: 9 Nov 2016

    Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method.

    Source:Elazar
    Published:6 Feb 2008
    4.3
    Medium

    CVE-2008-0624

    Last Modified: 9 Nov 2016

    Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623.

    Source:h07
    Published:6 Feb 2008
    4.3
    Medium

    CVE-2008-0623

    Last Modified: 9 Nov 2016

    Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.

    Source:h07
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0621

    Last Modified: 12 Jan 2017

    Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.

    Source:Metasploit
    Published:6 Feb 2008
    9.3
    Critical

    CVE-2008-0619

    Last Modified: 23 Apr 2026

    Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (persistent crash) via a long URI in a .M3U file.

    Source:securfrog
    Published:6 Feb 2008
    6.5
    Medium

    CVE-2008-0616

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Source:NBBN
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0614

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL commands via the pic parameter in a showpic action.

    Source:you_kn0w
    Published:6 Feb 2008
    5
    Medium

    CVE-2008-0613

    Last Modified: 14 Nov 2016

    Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter.

    Source:DSecRG
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0612

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:DSecRG
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0611

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:you_kn0w
    Published:6 Feb 2008
    9.3
    Critical

    CVE-2008-0610

    Last Modified: 30 Mar 2012

    Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value.

    Source:Metasploit
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0609

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Source:DSecRG
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0606

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.

    Source:S@BUN
    Published:6 Feb 2008
    4.3
    Medium

    CVE-2008-0605

    Last Modified: 21 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.

    Source:Alexandr Polyakov
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0603

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter in a viewlist task.

    Source:S@BUN
    Published:6 Feb 2008
    6.8
    Medium

    CVE-2008-0602

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter.

    Source:Trancek
    Published:6 Feb 2008
    7.5
    High

    CVE-2008-0601

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Source:ka0x
    Published:6 Feb 2008
    7.2
    High

    CVE-2008-0600

    Last Modified: 14 Nov 2016

    The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.

    Source:qaaz
    Published:9 Feb 2008
    9
    Critical

    CVE-2008-0590

    Last Modified: 14 Nov 2016

    Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.

    Source:securfrog
    Published:5 Feb 2008
    7.5
    High

    CVE-2008-0579

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in a list action.

    Source:S@BUN
    Published:5 Feb 2008
    4.3
    Medium

    CVE-2008-0574

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.

    Source:NBBN
    Published:5 Feb 2008
    7.2
    High

    CVE-2008-0573

    Last Modified: 28 Oct 2016

    IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request.

    Source:mu-b
    Published:5 Feb 2008
    6.8
    Medium

    CVE-2008-0572

    Last Modified: 14 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4) manage.inc.php, (5) mind.inc.php, and (6) sensory.inc.php in include/.

    Source:David Wharton
    Published:5 Feb 2008
    7.5
    High

    CVE-2008-0567

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/; and (4) BIFFwriter.php, (5) Workbook.php, (6) Worksheet.php, and (7) Format.php in excelwriter/Writer/.

    Source:Crackers_Child
    Published:5 Feb 2008
    6.8
    Medium

    CVE-2008-0566

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter.

    Source:Houssamix
    Published:5 Feb 2008
    6.8
    Medium

    CVE-2008-0565

    Last Modified: 16 Aug 2015

    SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:L0n3ly-H34rT
    Published:5 Feb 2008
    7.5
    High

    CVE-2008-0562

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:S@BUN
    Published:4 Feb 2008
    7.5
    High

    CVE-2008-0561

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:S@BUN
    Published:4 Feb 2008
    5
    Medium

    CVE-2008-0559

    Last Modified: 20 Jan 2014

    Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php.

    Source:muuratsalo
    Published:4 Feb 2008
    7.5
    High

    CVE-2008-0557

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:S@BUN
    Published:4 Feb 2008
    4.3
    Medium

    CVE-2008-0552

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:jekil
    Published:1 Feb 2008
    9.3
    Critical

    CVE-2008-0551

    Last Modified: 23 Apr 2026

    The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information.

    Source:plan-s
    Published:1 Feb 2008
    10
    Critical

    CVE-2008-0550

    Last Modified: 7 Jun 2018

    Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.

    Source:Metasploit
    Published:1 Feb 2008
    4.3
    Medium

    CVE-2008-0547

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.

    Source:BugReport.IR
    Published:1 Feb 2008
    7.5
    High

    CVE-2008-0546

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp.

    Source:BugReport.IR
    Published:1 Feb 2008
    7.5
    High

    CVE-2008-0545

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.

    Source:Stack
    Published:1 Feb 2008