Vulnerabilities (CVE)

Total 398612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6401 1 Jetik 1 Jetik-web 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the kat parameter.
CVE-2008-6400 1 Refbase 1 Refbase 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in refbase before 0.9.5 allows remote attackers to inject arbitrary web script or HTML via the headerMsg parameter to (1) show.php and (2) search.php. NOTE: some of these details are obtained from third party information.
CVE-2008-6399 1 Dnnsoftware 1 Dotnetnuke 2026-06-16 6.4 MEDIUM N/A
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
CVE-2008-6398 1 Eric Raymond 1 Sng 2026-06-16 6.9 MEDIUM N/A
sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.
CVE-2008-6397 1 Alcovebook 1 Sgml2x 2026-06-16 4.4 MEDIUM N/A
rlatex in AlcoveBook sgml2x 1.0.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVE-2008-6396 1 Celerondude 1 Uploader 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-6395 1 3com 1 Wireless 8760 Dual-radio 2026-06-16 7.8 HIGH N/A
The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request.
CVE-2008-6394 1 Cs-cart 1 Cs-cart 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the cs_cookies[customer_user_id] cookie parameter.
CVE-2008-6393 2 Jabber, Psi-im 2 Jabber Client, Psi 2026-06-16 10.0 HIGH N/A
PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.
CVE-2008-6392 1 1scripts 1 Z1exchange 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2008-6391 1 Nexusjnr 1 Jbook 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the username (user parameter).
CVE-2008-6390 1 Ocean12tech 1 Membership Manager Pro 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2008-6389 1 Aliensoftcorp 1 Rae Media Contact Management 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterprise allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.
CVE-2008-6388 1 4u2ges 1 Rapid Classified 2026-06-16 5.0 MEDIUM N/A
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb.
CVE-2008-6387 1 Activewebsoftwares 1 Quick Tree View .net 2026-06-16 5.0 MEDIUM N/A
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to qtv.mdb.
CVE-2008-6386 1 1scripts 1 Z1exchange 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in showads.php in Z1Exchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2008-6385 1 W3matter 1 Revsense 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
CVE-2008-6384 1 Drupal 1 Comment Mail 2026-06-16 6.8 MEDIUM N/A
Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack the authentication of administrators.
CVE-2008-6383 1 Drupal 2 Drupal, Storm 2026-06-16 6.0 MEDIUM N/A
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
CVE-2008-6382 1 Aspportal 1 Aspportal 2026-06-16 5.0 MEDIUM N/A
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb.