6.8
    Medium

    CVE-2008-0458

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlang parameter to index.php.

    Source:The_HuliGun
    Published:25 Jan 2008
    10
    Critical

    CVE-2008-0457

    Last Modified: 14 Nov 2016

    Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.

    Source:titon
    Published:7 Feb 2008
    4.3
    Medium

    CVE-2008-0455

    Last Modified: 31 Jan 2017

    Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

    Source:Stefano Di Paola
    Published:25 Jan 2008
    6.8
    Medium

    CVE-2008-0453

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

    Source:S@BUN
    Published:24 Jan 2008
    5
    Medium

    CVE-2008-0452

    Last Modified: 28 Oct 2016

    Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a viewart action.

    Source:Khashayar Fereidani
    Published:24 Jan 2008
    7.5
    High

    CVE-2008-0451

    Last Modified: 20 Jan 2014

    Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) siteadmin/article-edit.php; and unspecified parameters to (2) submitted-edit.php, (3) page-edit.php, (4) section-edit.php, (5) staff-edit.php, and (6) staff-access.php in siteadmin/.

    Source:RawSecurity.org
    Published:24 Jan 2008
    7.5
    High

    CVE-2008-0447

    Last Modified: 28 Oct 2016

    SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter.

    Source:Khashayar Fereidani
    Published:24 Jan 2008
    7.5
    High

    CVE-2008-0446

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:24 Jan 2008
    10
    Critical

    CVE-2008-0443

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:24 Jan 2008
    7.5
    High

    CVE-2008-0442

    Last Modified: 27 Oct 2016

    PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:RoMaNcYxHaCkEr
    Published:24 Jan 2008
    5
    Medium

    CVE-2008-0440

    Last Modified: 23 Apr 2026

    AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

    Source:t0pP8uZz
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0439

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.

    Source:NBBN
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0438

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf.

    Source:Jan Fry
    Published:23 Jan 2008
    10
    Critical

    CVE-2008-0437

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0436

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target parameter.

    Source:Doz
    Published:23 Jan 2008
    5
    Medium

    CVE-2008-0435

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action.

    Source:shinmai
    Published:23 Jan 2008
    9.3
    Critical

    CVE-2008-0434

    Last Modified: 23 Apr 2026

    Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.

    Source:hempel
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0433

    Last Modified: 20 Jan 2014

    PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.

    Source:H-T Team
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0432

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Source:H-T Team
    Published:23 Jan 2008
    5
    Medium

    CVE-2008-0431

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.

    Source:MhZ91
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0430

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.

    Source:Ded MustD!e
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0429

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.

    Source:t0pP8uZz
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0428

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.

    Source:BugReport.IR
    Published:23 Jan 2008
    7.8
    High

    CVE-2008-0427

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:BugReport.IR
    Published:23 Jan 2008
    5
    Medium

    CVE-2008-0425

    Last Modified: 14 Nov 2016

    Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter.

    Source:Houssamix
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0424

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter.

    Source:The_HuliGun
    Published:23 Jan 2008
    6.8
    Medium

    CVE-2008-0423

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.steps.access_error.php, (2) inc.steps.check_login.php, or (3) inc.steps.init_system.php in admin/functions/.

    Source:QTRinux
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0422

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Virangar Security
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0421

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in a rate command.

    Source:RST/GHC
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0418

    Last Modified: 20 Jan 2014

    Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

    Source:Gerry Eisenhaur
    Published:7 Feb 2008
    6.8
    Medium

    CVE-2008-0411

    Last Modified: 31 Jan 2014

    Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.

    Source:Will Drewry
    Published:27 Feb 2008
    5
    Medium

    CVE-2008-0406

    Last Modified: 18 Dec 2016

    HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.

    Source:Felipe M. Aragon
    Published:28 Jan 2008
    5.5
    Medium

    CVE-2008-0403

    Last Modified: 23 Apr 2026

    The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.

    Source:DarkFig
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0400

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter to default.php.

    Source:trew
    Published:23 Jan 2008
    6.8
    Medium

    CVE-2008-0399

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods.

    Source:rgod
    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-0398

    Last Modified: 27 Oct 2016

    Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment form.

    Source:shinmai
    Published:23 Jan 2008
    6.8
    Medium

    CVE-2008-0397

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to comments.php and (2) an unspecified parameter to view.php.

    Source:shinmai
    Published:23 Jan 2008
    7.8
    High

    CVE-2008-0396

    Last Modified: 20 Jan 2014

    Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Security for Fileservers and Enterprise Manager (BDEM), allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.

    Source:Oliver Karow
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0394

    Last Modified: 23 Apr 2026

    Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.

    Source:prdelka
    Published:23 Jan 2008
    5.8
    Medium

    CVE-2008-0393

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.

    Source:Syndr0me
    Published:23 Jan 2008
    9.3
    Critical

    CVE-2008-0392

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.

    Source:shinnai
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0391

    Last Modified: 23 Apr 2026

    inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.

    Source:tomplixsee
    Published:23 Jan 2008
    7.5
    High

    CVE-2008-0390

    Last Modified: 26 Oct 2016

    stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.

    Source:k1tk4t
    Published:23 Jan 2008
    6.8
    Medium

    CVE-2008-0388

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI.

    Source:websec Team
    Published:23 Jan 2008
    7.8
    High

    CVE-2008-0387

    Last Modified: 20 Jan 2014

    Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via crafted (1) op_receive, (2) op_start, (3) op_start_and_receive, (4) op_send, (5) op_start_and_send, and (6) op_start_send_and_receive XDR requests, which triggers memory corruption.

    Source:Damian Frizza
    Published:29 Jan 2008
    4.9
    Medium

    CVE-2008-0384

    Last Modified: 9 Nov 2016

    OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.

    Source:Hunger
    Published:22 Jan 2008
    7.5
    High

    CVE-2008-0383

    Last Modified: 20 Jan 2014

    Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.

    Source:waraxe
    Published:22 Jan 2008
    7.5
    High

    CVE-2008-0382

    Last Modified: 27 Oct 2016

    Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

    Source:waraxe
    Published:22 Jan 2008
    10
    Critical

    CVE-2008-0380

    Last Modified: 26 Oct 2016

    Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.

    Source:rgod
    Published:22 Jan 2008
    9.3
    Critical

    CVE-2008-0379

    Last Modified: 27 Oct 2016

    Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.

    Source:shinnai
    Published:22 Jan 2008