7.5
    High

    CVE-2008-0267

    Last Modified: 17 Jan 2014

    Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.

    Source:L4teral
    Published:15 Jan 2008
    2.6
    Low

    CVE-2008-0266

    Last Modified: 17 Jan 2014

    Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.

    Source:L4teral
    Published:15 Jan 2008
    4.3
    Medium

    CVE-2008-0265

    Last Modified: 19 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories.

    Source:nnposter
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0262

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.

    Source:ka0x
    Published:15 Jan 2008
    5
    Medium

    CVE-2008-0260

    Last Modified: 8 Nov 2016

    minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.

    Source:Houssamix
    Published:15 Jan 2008
    6.4
    Medium

    CVE-2008-0259

    Last Modified: 8 Nov 2016

    Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters.

    Source:Houssamix
    Published:15 Jan 2008
    4.3
    Medium

    CVE-2008-0258

    Last Modified: 17 Jan 2014

    Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:Christophe VG
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0256

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.

    Source:trew
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0255

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.

    Source:Eugene Minaev
    Published:15 Jan 2008
    6.8
    Medium

    CVE-2008-0254

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.

    Source:ka0x
    Published:15 Jan 2008
    7.5
    High

    CVE-2008-0253

    Last Modified: 26 Oct 2016

    SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.

    Source:JosS
    Published:15 Jan 2008
    10
    Critical

    CVE-2008-0251

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.

    Source:Cold Zero
    Published:12 Jan 2008
    9.3
    Critical

    CVE-2008-0250

    Last Modified: 17 Nov 2016

    Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.

    Source:shinnai
    Published:12 Jan 2008
    5
    Medium

    CVE-2008-0249

    Last Modified: 8 Nov 2016

    PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only be an issue in limited environments.

    Source:MhZ91
    Published:12 Jan 2008
    9.3
    Critical

    CVE-2008-0248

    Last Modified: 25 Oct 2016

    Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.

    Source:Elazar
    Published:12 Jan 2008
    10
    Critical

    CVE-2008-0246

    Last Modified: 23 Apr 2026

    admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.

    Source:Dj7xpl
    Published:12 Jan 2008
    7.5
    High

    CVE-2008-0245

    Last Modified: 23 Apr 2026

    admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.

    Source:Dj7xpl
    Published:12 Jan 2008
    10
    Critical

    CVE-2008-0244

    Last Modified: 23 Apr 2026

    SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.

    Source:Luigi Auriemma
    Published:12 Jan 2008
    4.3
    Medium

    CVE-2008-0240

    Last Modified: 17 Jan 2014

    /idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."

    Source:Jan Fry & Adrian Pastor
    Published:11 Jan 2008
    4.3
    Medium

    CVE-2008-0239

    Last Modified: 17 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.

    Source:Jan Fry & Adrian Pastor
    Published:11 Jan 2008
    6.8
    Medium

    CVE-2008-0237

    Last Modified: 14 Nov 2016

    The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.

    Source:shinnai
    Published:11 Jan 2008
    5.8
    Medium

    CVE-2008-0236

    Last Modified: 25 Oct 2016

    An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.

    Source:shinnai
    Published:11 Jan 2008
    9.3
    Critical

    CVE-2008-0234

    Last Modified: 8 Nov 2016

    Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.

    Source:Luigi Auriemma
    Published:11 Jan 2008
    7.5
    High

    CVE-2008-0233

    Last Modified: 8 Nov 2016

    Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

    Source:KiNgOfThEwOrLd
    Published:11 Jan 2008
    7.5
    High

    CVE-2008-0232

    Last Modified: 8 Nov 2016

    Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.

    Source:KiNgOfThEwOrLd
    Published:11 Jan 2008
    7.5
    High

    CVE-2008-0231

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via ".." sequences in the page parameter. NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments.

    Source:DSecRG
    Published:11 Jan 2008
    7.5
    High

    CVE-2008-0230

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.

    Source:Cold Zero
    Published:11 Jan 2008
    9.3
    Critical

    CVE-2008-0228

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.

    Published:10 Jan 2008
    7.5
    High

    CVE-2008-0226

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.

    Source:MC
    Published:10 Jan 2008
    6.4
    Medium

    CVE-2008-0225

    Last Modified: 22 Nov 2016

    Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.

    Source:Luigi Auriemma
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.

    Source:Eugene Minaev
    Published:10 Jan 2008
    7.5
    High

    CVE-2008-0222

    Last Modified: 8 Nov 2016

    Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.

    Source:Houssamix
    Published:10 Jan 2008
    9.3
    Critical

    CVE-2008-0221

    Last Modified: 25 Oct 2016

    Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:10 Jan 2008
    7.5
    High

    CVE-2008-0220

    Last Modified: 25 Oct 2016

    Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.

    Source:Elazar
    Published:10 Jan 2008
    7.5
    High

    CVE-2008-0219

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.

    Source:ka0x
    Published:10 Jan 2008
    4.3
    Medium

    CVE-2008-0218

    Last Modified: 17 Jan 2014

    Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ekin0x
    Published:10 Jan 2008
    6.4
    Medium

    CVE-2008-0210

    Last Modified: 23 Apr 2026

    Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.

    Source:Eugene Minaev
    Published:10 Jan 2008
    4.3
    Medium

    CVE-2008-0207

    Last Modified: 17 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.

    Source:MustLive
    Published:10 Jan 2008
    4.3
    Medium

    CVE-2008-0193

    Last Modified: 4 May 2017

    Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through 2.3.x, allows remote attackers to inject arbitrary web script or HTML via the backup parameter in a wp-db-backup.php action to wp-admin/edit.php.

    Source:3APA3A
    Published:10 Jan 2008
    4.3
    Medium

    CVE-2008-0192

    Last Modified: 4 May 2017

    Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the popuptitle parameter to (1) wp-admin/post.php or (2) wp-admin/page-new.php.

    Source:3APA3A
    Published:10 Jan 2008
    4.3
    Medium

    CVE-2008-0190

    Last Modified: 16 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.

    Source:MustLive
    Published:10 Jan 2008
    7.5
    High

    CVE-2008-0187

    Last Modified: 24 Oct 2016

    SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.

    Source:BackDoor
    Published:9 Jan 2008
    4.3
    Medium

    CVE-2008-0186

    Last Modified: 30 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.

    Source:Virangar Security
    Published:9 Jan 2008
    7.5
    High

    CVE-2008-0185

    Last Modified: 30 Dec 2016

    SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the pid parameter in a profile page (possibly profile.php).

    Source:Virangar Security
    Published:9 Jan 2008
    6.4
    Medium

    CVE-2008-0184

    Last Modified: 17 Jan 2014

    Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary files via an encoded "/" ("%2F") in the file parameter.

    Source:p4imi0
    Published:9 Jan 2008
    4.3
    Medium

    CVE-2008-0178

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Source:Tomasz Kuczynski
    Published:4 Feb 2008
    7.8
    High

    CVE-2008-0177

    Last Modified: 23 Apr 2026

    The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

    Source:mu-b
    Published:7 Feb 2008
    7.5
    High

    CVE-2008-0175

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to the main virtual directory.

    Source:Kevin Finisterre
    Published:29 Jan 2008
    4.6
    Medium

    CVE-2008-0167

    Last Modified: 14 Nov 2016

    The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.

    Source:RoMaNcYxHaCkEr
    Published:18 May 2008
    7.5
    High

    CVE-2008-0166

    Last Modified: 3 Jul 2017

    OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.

    Source:Markus Mueller
    Published:13 May 2008