6.8
    Medium

    CVE-2008-0159

    Last Modified: 11 Jan 2017

    SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.

    Source:Eugene Minaev
    Published:9 Jan 2008
    5
    Medium

    CVE-2008-0158

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to read arbitrary files via a .. (dot dot) in the aux_page parameter.

    Source:Fisher762
    Published:9 Jan 2008
    7.5
    High

    CVE-2008-0157

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_temp_id parameter in a cookie.

    Source:Eugene Minaev
    Published:9 Jan 2008
    4.3
    Medium

    CVE-2008-0155

    Last Modified: 8 Nov 2016

    Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitrary web script or HTML via the c parameter.

    Source:seaofglass
    Published:9 Jan 2008
    7.5
    High

    CVE-2008-0154

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL commands the c parameter.

    Source:seaofglass
    Published:9 Jan 2008
    5
    Medium

    CVE-2008-0153

    Last Modified: 20 Jan 2014

    telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference.

    Source:Luigi Auriemma
    Published:9 Jan 2008
    10
    Critical

    CVE-2008-0151

    Last Modified: 20 Jan 2014

    Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Telnet request with long options.

    Source:Luigi Auriemma
    Published:9 Jan 2008
    5
    Medium

    CVE-2008-0149

    Last Modified: 25 Oct 2016

    TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.

    Source:Houssamix
    Published:9 Jan 2008
    10
    Critical

    CVE-2008-0148

    Last Modified: 25 Oct 2016

    TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.

    Source:Houssamix
    Published:9 Jan 2008
    6.8
    Medium

    CVE-2008-0147

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.

    Source:Eugene Minaev
    Published:9 Jan 2008
    4.3
    Medium

    CVE-2008-0146

    Last Modified: 16 Jan 2014

    Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.

    Source:vivek_infosec
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0144

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.

    Source:S.W.A.T.
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0143

    Last Modified: 24 Oct 2016

    PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter.

    Source:Crackers_Child
    Published:8 Jan 2008
    6.8
    Medium

    CVE-2008-0142

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.

    Source:The:Paradox
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0141

    Last Modified: 23 Apr 2026

    actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.

    Source:The:Paradox
    Published:8 Jan 2008
    6.4
    Medium

    CVE-2008-0140

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.

    Source:Eugene Minaev
    Published:8 Jan 2008
    6.8
    Medium

    CVE-2008-0139

    Last Modified: 8 Nov 2016

    Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

    Source:Eugene Minaev
    Published:8 Jan 2008
    6.8
    Medium

    CVE-2008-0138

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.

    Source:Eugene Minaev
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0137

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

    Source:Crackers_Child
    Published:8 Jan 2008
    5
    Medium

    CVE-2008-0135

    Last Modified: 23 Apr 2026

    Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.

    Source:ViRuSMaN
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0133

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.

    Source:x0kster
    Published:8 Jan 2008
    5
    Medium

    CVE-2008-0132

    Last Modified: 20 Jan 2014

    Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.

    Source:Luigi Auriemma
    Published:8 Jan 2008
    6.8
    Medium

    CVE-2008-0129

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.

    Source:EgiX
    Published:8 Jan 2008
    5
    Medium

    CVE-2008-0128

    Last Modified: 23 Apr 2026

    The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

    Published:20 Dec 2006
    8.8
    High

    CVE-2008-0127

    Last Modified: 14 Nov 2016

    The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long initial authentication packet.

    Source:Leon Juranic
    Published:10 Jan 2008
    4.3
    Medium

    CVE-2008-0125

    Last Modified: 5 Feb 2014

    Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.

    Source:Hanno Boeck
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-0123

    Last Modified: 17 Jan 2014

    Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

    Source:Hanno Bock
    Published:12 Jan 2008
    9.3
    Critical

    CVE-2008-0118

    Last Modified: 5 Feb 2014

    Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."

    Source:anonymous
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0117

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."

    Source:zha0
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0116

    Last Modified: 23 Apr 2026

    Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."

    Source:zha0
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0115

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."

    Source:zha0
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0114

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.

    Source:zha0
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0113

    Last Modified: 27 Oct 2016

    Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."

    Source:Marsu
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0112

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."

    Source:zha0
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0111

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."

    Source:zha0
    Published:11 Mar 2008
    9.3
    Critical

    CVE-2008-0108

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."

    Source:chujwamwdupe
    Published:12 Feb 2008
    9.3
    Critical

    CVE-2008-0105

    Last Modified: 23 Apr 2026

    Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."

    Source:chujwamwdupe
    Published:12 Feb 2008
    7.5
    High

    CVE-2008-0100

    Last Modified: 20 Jan 2014

    Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.

    Source:Luigi Auriemma
    Published:8 Jan 2008
    6.8
    Medium

    CVE-2008-0099

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.

    Source:The:Paradox
    Published:8 Jan 2008
    7.5
    High

    CVE-2008-0096

    Last Modified: 20 Jan 2014

    Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.

    Source:Luigi Auriemma
    Published:8 Jan 2008
    5
    Medium

    CVE-2008-0095

    Last Modified: 9 Apr 2014

    The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.

    Source:greyvoip
    Published:8 Jan 2008
    6.4
    Medium

    CVE-2008-0094

    Last Modified: 16 Jan 2014

    Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.

    Source:AmnPardaz Security Research Team
    Published:8 Jan 2008
    4.3
    Medium

    CVE-2008-0092

    Last Modified: 25 May 2016

    Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:RusH
    Published:4 Jan 2008
    6.4
    Medium

    CVE-2008-0091

    Last Modified: 8 Nov 2016

    Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.

    Source:GoLd_M
    Published:4 Jan 2008
    5
    Medium

    CVE-2008-0090

    Last Modified: 24 Nov 2016

    A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.

    Source:anonymous
    Published:4 Jan 2008
    7.5
    High

    CVE-2008-0089

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via the UID parameter.

    Source:Krit
    Published:4 Jan 2008
    9.8
    Critical

    CVE-2008-0081

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.

    Source:zha0
    Published:16 Jan 2008
    6.8
    Medium

    CVE-2008-0073

    Last Modified: 23 Apr 2026

    Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.

    Source:j0rgan
    Published:24 Mar 2008
    4.3
    Medium

    CVE-2008-0071

    Last Modified: 9 Mar 2018

    The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.

    Source:Exodus
    Published:16 Jun 2008
    6.8
    Medium

    CVE-2008-0069

    Last Modified: 25 Oct 2016

    Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.

    Source:haluznik
    Published:2 Apr 2008