5
    Medium

    CVE-2008-0542

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:tomplixsee
    Published:1 Feb 2008
    4.3
    Medium

    CVE-2008-0541

    Last Modified: 28 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.

    Source:tomplixsee
    Published:1 Feb 2008
    4.3
    Medium

    CVE-2008-0540

    Last Modified: 13 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.

    Source:Omer Singer
    Published:1 Feb 2008
    4.3
    Medium

    CVE-2008-0539

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.

    Source:nnposter
    Published:1 Feb 2008
    6.8
    Medium

    CVE-2008-0538

    Last Modified: 14 Nov 2016

    Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to login.php, the (2) id parameter to display.php, and unspecified other vectors. NOTE: some of these details are obtained from third party information.

    Source:Charles Hooper
    Published:1 Feb 2008
    4.3
    Medium

    CVE-2008-0533

    Last Modified: 22 Jun 2017

    Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.

    Source:felix
    Published:14 Mar 2008
    10
    Critical

    CVE-2008-0532

    Last Modified: 4 Feb 2014

    Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.

    Source:felix
    Published:14 Mar 2008
    5
    Medium

    CVE-2008-0521

    Last Modified: 14 Nov 2016

    Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via a .. (dot dot) in the uri parameter to dispatcher.php in (1) examples/dispatcher/framework/, (2) examples/dispatcher/, (3) examples/wizard/, and (4) PHP/, different vectors than CVE-2008-0545.

    Source:Stack
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0520

    Last Modified: 9 Nov 2016

    Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.

    Source:enter_the_dragon
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0519

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0518

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0517

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0515

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0514

    Last Modified: 31 Oct 2016

    SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.

    Source:S@BUN
    Published:31 Jan 2008
    7.8
    High

    CVE-2008-0513

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to parser/parser.php, as demonstrated by a filename ending with %00.gif, a different vector than CVE-2005-1840.

    Source:DSecRG
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0512

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0511

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0510

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.

    Source:S@BUN
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0507

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:enter_the_dragon
    Published:31 Jan 2008
    6.8
    Medium

    CVE-2008-0506

    Last Modified: 6 Mar 2011

    include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.

    Source:Metasploit
    Published:31 Jan 2008
    6.5
    Medium

    CVE-2008-0504

    Last Modified: 14 Nov 2016

    Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.

    Source:bazik
    Published:31 Jan 2008
    6.8
    Medium

    CVE-2008-0503

    Last Modified: 14 Nov 2016

    Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute arbitrary PHP code via the filedata parameter.

    Source:GoLd_M
    Published:31 Jan 2008
    7.5
    High

    CVE-2008-0502

    Last Modified: 9 Nov 2016

    PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the template_path parameter.

    Source:Houssamix
    Published:31 Jan 2008
    5.8
    Medium

    CVE-2008-0501

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI.

    Source:S.W.A.T.
    Published:30 Jan 2008
    7.5
    High

    CVE-2008-0498

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php.

    Source:D4m14n
    Published:30 Jan 2008
    4.3
    Medium

    CVE-2008-0497

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, which is not quoted when processing PHP_SELF.

    Source:Alexandr Polyakov
    Published:30 Jan 2008
    4.3
    Medium

    CVE-2008-0496

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web script or HTML via the limit parameter in a search action.

    Source:ShaFuck31
    Published:30 Jan 2008
    9.3
    Critical

    CVE-2008-0493

    Last Modified: 31 Oct 2016

    fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafted FlashPix (.FPX) file, which triggers heap corruption. NOTE: some of these details are obtained from third party information.

    Source:Marsu
    Published:30 Jan 2008
    6.8
    Medium

    CVE-2008-0492

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:30 Jan 2008
    7.5
    High

    CVE-2008-0491

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the album parameter.

    Source:Houssamix
    Published:30 Jan 2008
    7.5
    High

    CVE-2008-0490

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Houssamix
    Published:30 Jan 2008
    5
    Medium

    CVE-2008-0489

    Last Modified: 20 Jan 2014

    Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Source:p4imi0
    Published:30 Jan 2008
    7.5
    High

    CVE-2008-0488

    Last Modified: 20 Jan 2014

    Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the location parameter.

    Source:Sw33t h4cK3r
    Published:30 Jan 2008
    7.5
    High

    CVE-2008-0487

    Last Modified: 20 Jan 2014

    Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Source:T_L_O_T_D
    Published:30 Jan 2008
    9.3
    Critical

    CVE-2008-0485

    Last Modified: 23 Nov 2016

    Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.

    Source:Felipe Manzano
    Published:5 Feb 2008
    5
    Medium

    CVE-2008-0481

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.

    Source:BugReport.IR
    Published:29 Jan 2008
    5
    Medium

    CVE-2008-0480

    Last Modified: 28 Oct 2016

    Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.

    Source:BugReport.IR
    Published:29 Jan 2008
    5
    Medium

    CVE-2008-0479

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter.

    Source:BugReport.IR
    Published:29 Jan 2008
    6.8
    Medium

    CVE-2008-0478

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as demonstrated by sending a certain CLIENT_IP HTTP header in an enter action to index.php, and injecting PHP sequences into files/enter.set, which is then included by index.php.

    Source:RST/GHC
    Published:29 Jan 2008
    10
    Critical

    CVE-2008-0477

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:29 Jan 2008
    4.3
    Medium

    CVE-2008-0474

    Last Modified: 1 Aug 2012

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) showlink parameter to jsp/DiscoveryProfiles.jsp; the (2) attributeIDs, (3) attributeToSelect, (4) redirectto, and (5) resourceid parameters to (a) jsp/ThresholdActionConfiguration.jsp; the (6) page and (7) redirect parameters to (b) jsp/UpdateGlobalSettings.jsp; and the (8) haid and (9) returnpath parameters to (c) showTile.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Vulnerability-Lab
    Published:29 Jan 2008
    6.4
    Medium

    CVE-2008-0473

    Last Modified: 27 Oct 2016

    RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.

    Source:BugReport.IR
    Published:29 Jan 2008
    9.3
    Critical

    CVE-2008-0470

    Last Modified: 28 Oct 2016

    A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.

    Source:h07
    Published:29 Jan 2008
    7.5
    High

    CVE-2008-0469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action.

    Source:0in
    Published:29 Jan 2008
    7.5
    High

    CVE-2008-0468

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Houssamix
    Published:29 Jan 2008
    5
    Medium

    CVE-2008-0466

    Last Modified: 28 Oct 2016

    Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.

    Source:BugReport.IR
    Published:28 Jan 2008
    5
    Medium

    CVE-2008-0465

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter.

    Source:fuzion
    Published:25 Jan 2008
    5
    Medium

    CVE-2008-0464

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Source:Arno Toll
    Published:25 Jan 2008
    6.8
    Medium

    CVE-2008-0461

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. NOTE: some of these details are obtained from third party information.

    Source:RST/GHC
    Published:25 Jan 2008
    6.8
    Medium

    CVE-2008-0459

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the update parameter.

    Source:Stack
    Published:25 Jan 2008