6.8
    Medium

    CVE-2008-0376

    Last Modified: 27 Oct 2016

    PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter.

    Source:RoMaNcYxHaCkEr
    Published:22 Jan 2008
    5
    Medium

    CVE-2008-0372

    Last Modified: 19 Jan 2014

    8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP request.

    Source:nnposter
    Published:22 Jan 2008
    6.8
    Medium

    CVE-2008-0371

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in aliTalk 1.9.1.1, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) the mohit parameter to (a) inc/receivertwo.php; and allow remote attackers to execute arbitrary SQL commands via (2) the id parameter to (b) inc/usercp.php, related to functionz/usercp.php; or (3) the username parameter to (c) admin/index.php, related to functionz/first_process.php, or (d) index.php. NOTE: some of these details are obtained from third party information.

    Source:tomplixsee
    Published:22 Jan 2008
    7.2
    High

    CVE-2008-0365

    Last Modified: 20 Jan 2014

    Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.

    Source:Sebastian Gottschalk
    Published:18 Jan 2008
    5
    Medium

    CVE-2008-0364

    Last Modified: 9 Dec 2016

    Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string representing a client version identifier.

    Source:Luigi Auriemma
    Published:18 Jan 2008
    4.3
    Medium

    CVE-2008-0361

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter.

    Source:JosS
    Published:18 Jan 2008
    7.5
    High

    CVE-2008-0360

    Last Modified: 9 Nov 2016

    Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php.

    Source:DSecRG
    Published:18 Jan 2008
    4.3
    Medium

    CVE-2008-0359

    Last Modified: 9 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.

    Source:DSecRG
    Published:18 Jan 2008
    6.8
    Medium

    CVE-2008-0358

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.

    Source:Silentz
    Published:18 Jan 2008
    4.3
    Medium

    CVE-2008-0357

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

    Source:Scary-Boys
    Published:18 Jan 2008
    7.5
    High

    CVE-2008-0355

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.

    Source:Stack
    Published:18 Jan 2008
    7.5
    High

    CVE-2008-0353

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. NOTE: some of these details are obtained from third party information.

    Source:Khashayar Fereidani
    Published:18 Jan 2008
    7.8
    High

    CVE-2008-0352

    Last Modified: 8 Nov 2016

    The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).

    Source:Clemens Kurtenbach
    Published:17 Jan 2008
    5
    Medium

    CVE-2008-0351

    Last Modified: 8 Nov 2016

    admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.

    Source:BlackHawk
    Published:17 Jan 2008
    7.5
    High

    CVE-2008-0350

    Last Modified: 8 Nov 2016

    admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.

    Source:BlackHawk
    Published:17 Jan 2008
    10
    Critical

    CVE-2008-0339

    Last Modified: 17 Jan 2014

    Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.

    Source:sh2kerr
    Published:17 Jan 2008
    5
    Medium

    CVE-2008-0338

    Last Modified: 25 Nov 2016

    Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.

    Source:Hamid Ebadi
    Published:17 Jan 2008
    7.5
    High

    CVE-2008-0337

    Last Modified: 25 Nov 2016

    Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.

    Source:Hamid Ebadi
    Published:17 Jan 2008
    2.6
    Low

    CVE-2008-0334

    Last Modified: 19 Jan 2014

    Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.

    Source:fuzion
    Published:17 Jan 2008
    5
    Medium

    CVE-2008-0333

    Last Modified: 26 Oct 2016

    Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter.

    Source:-=M.o.B=-
    Published:17 Jan 2008
    5
    Medium

    CVE-2008-0332

    Last Modified: 9 Nov 2016

    Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Source:DSecRG
    Published:17 Jan 2008
    5
    Medium

    CVE-2008-0329

    Last Modified: 8 Nov 2016

    LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter.

    Source:ka0x
    Published:17 Jan 2008
    7.5
    High

    CVE-2008-0328

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:17 Jan 2008
    7.5
    High

    CVE-2008-0327

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:17 Jan 2008
    7.5
    High

    CVE-2008-0326

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

    Source:Khashayar Fereidani
    Published:17 Jan 2008
    7.5
    High

    CVE-2008-0325

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Khashayar Fereidani
    Published:17 Jan 2008
    4.9
    Medium

    CVE-2008-0324

    Last Modified: 23 Apr 2026

    Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.

    Source:mu-b
    Published:17 Jan 2008
    9.3
    Critical

    CVE-2008-0320

    Last Modified: 25 May 2012

    Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.

    Source:Metasploit
    Published:17 Apr 2008
    9.3
    Critical

    CVE-2008-0311

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request.

    Source:Metasploit
    Published:6 Apr 2008
    6.9
    Medium

    CVE-2008-0310

    Last Modified: 17 Nov 2016

    Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.

    Source:qaaz
    Published:7 Apr 2008
    7.5
    High

    CVE-2008-0301

    Last Modified: 15 Nov 2016

    Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors.

    Source:RedTeam Pentesting
    Published:11 Mar 2008
    6.8
    Medium

    CVE-2008-0300

    Last Modified: 15 Nov 2016

    mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences.

    Source:RedTeam Pentesting
    Published:11 Mar 2008
    4.3
    Medium

    CVE-2008-0298

    Last Modified: 17 Jan 2014

    KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.

    Source:David Barroso
    Published:16 Jan 2008
    5
    Medium

    CVE-2008-0297

    Last Modified: 26 Oct 2016

    PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.

    Source:Pr0metheuS
    Published:16 Jan 2008
    10
    Critical

    CVE-2008-0296

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.

    Source:j0rgan
    Published:16 Jan 2008
    8.5
    High

    CVE-2008-0295

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.

    Source:j0rgan
    Published:16 Jan 2008
    7.5
    High

    CVE-2008-0291

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:JosS
    Published:16 Jan 2008
    7.5
    High

    CVE-2008-0290

    Last Modified: 8 Nov 2016

    Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.

    Source:j0j0
    Published:16 Jan 2008
    6.8
    Medium

    CVE-2008-0289

    Last Modified: 17 Jan 2014

    PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: a second vector might exist via the l parameter. NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year."

    Source:ShipNX
    Published:16 Jan 2008
    7.5
    High

    CVE-2008-0288

    Last Modified: 8 Nov 2016

    Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.

    Source:Raw Security
    Published:16 Jan 2008
    6.8
    Medium

    CVE-2008-0287

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php.

    Source:k1n9k0ng
    Published:16 Jan 2008
    7.5
    High

    CVE-2008-0286

    Last Modified: 19 Jan 2014

    SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.

    Source:Xcross87
    Published:16 Jan 2008
    6.8
    Medium

    CVE-2008-0283

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Houssamix
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0282

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.

    Source:j0j0
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0281

    Last Modified: 17 Jan 2014

    SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.

    Source:consultant.securite
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0280

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.

    Source:Virangar Security
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0279

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter. NOTE: the categorie parameter might also be affected.

    Source:j0j0
    Published:15 Jan 2008
    6
    Medium

    CVE-2008-0278

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.

    Source:nonroot
    Published:15 Jan 2008
    6
    Medium

    CVE-2008-0270

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.

    Source:TheDefaced
    Published:15 Jan 2008
    4.3
    Medium

    CVE-2008-0268

    Last Modified: 17 Jan 2014

    Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Source:L4teral
    Published:15 Jan 2008