CVE Database - 2008

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

3144
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2008-5807

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) Testproject Names and (2) Testplan Names in planEdit.php, and possibly (3) Testcaseprefixes in projectview.tpl.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5806

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information.

SQL Injection
WAF: High

CVE-2008-5805

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828.

SQL Injection
WAF: High

CVE-2008-5804

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.

SQL Injection
WAF: High

CVE-2008-5803

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field). NOTE: some of these details are obtained from third party information.

SQL Injection
WAF: High

CVE-2008-5802

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

SQL Injection
WAF: High

CVE-2008-5801

HIGH
10.00 CVSS 2.0

Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.

Code Injection
WAF: Medium

CVE-2008-5800

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the Wir ber uns [sic] (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2008-5799

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Wir ber uns (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5798

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the CMS Poll system (cms_poll) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2008-5797

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2008-5796

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2008-5795

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5794

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

Path Traversal
WAF: High

CVE-2008-5793

MEDIUM
6.80 CVSS 2.0

Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php in Recly/Clickheat/, and (d) Recly/common/GlobalVariables.php; and the (2) mosConfig_absolute_path parameter to (e) _main.php and (f) main.php in includes/heatmap, and (g) includes/overview/main.php.

Code Injection
WAF: Medium

CVE-2008-5792

MEDIUM
6.80 CVSS 2.0

PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: the researcher also points out the analogous directory traversal issue.

Code Injection
WAF: Medium

CVE-2008-5790

HIGH
7.50 CVSS 2.0

Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) add.php and (b) competitions.php in includes/competitions/, and the (2) mosConfig_absolute_path parameter to (c) includes/settings/settings.php.

Code Injection
WAF: Medium

CVE-2008-5789

HIGH
7.50 CVSS 2.0

Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and the (2) GLOBALS[mosConfig_absolute_path] parameter to (d) includes/tmsp/subscription.php.

Code Injection
WAF: Medium

CVE-2008-5788

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2008-5787

MEDIUM
5.40 CVSS 2.0

Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction with a show action.

Path Traversal
WAF: High

CVE-2008-5786

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Silva Find extension 1.1.5 and earlier in Silva 1.x before 1.6.3.2, Silva 2.0 before 2.0.12.2, and Silva 2.1 before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the fulltext parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5785

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

SQL Injection
WAF: High

CVE-2008-5783

HIGH
7.50 CVSS 2.0

admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

Improper Authentication
WAF: Low

CVE-2008-5782

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

SQL Injection
WAF: High

CVE-2008-5781

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in right.php in Cant Find A Gaming CMS (CFAGCMS) 1.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the title parameter.

SQL Injection
WAF: High

CVE-2008-5779

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2008-5778

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

SQL Injection
WAF: High

CVE-2008-5777

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the cid parameter.

SQL Injection
WAF: High

CVE-2008-5776

HIGH
7.50 CVSS 2.0

Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) action parameter to admin.php and the (2) get parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Path Traversal
WAF: High

CVE-2008-5775

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2008-5774

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to (a) type.asp and (b) type2.asp and the (2) iPro parameter to (c) detail.asp.

SQL Injection
WAF: High

CVE-2008-5772

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp.

SQL Injection
WAF: High

CVE-2008-5771

HIGH
7.50 CVSS 2.0

Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

Path Traversal
WAF: High

CVE-2008-5770

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5769

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer before 6.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) folder parameter to mailCompose.php or the (2) daytime parameter to calendarEdit.php. NOTE: some of these details are obtained from third party information.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5768

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2008-5767

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands via the authorID parameter.

SQL Injection
WAF: High

CVE-2008-5766

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection
WAF: High

CVE-2008-5764

HIGH
9.30 CVSS 2.0

PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

Code Injection
WAF: Medium

CVE-2008-5763

HIGH
7.50 CVSS 2.0

PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter.

Code Injection
WAF: Medium

CVE-2008-5761

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter to the default URI; (2) the foto parameter to photo.php in the 05_Foto module; or (3) the name parameter in an insertrecord action to index.php in the 08_Files module, as demonstrated by injection within a SRC attribute of an IFRAME element.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5760

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in error413.php in Kerio MailServer before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via the sent parameter. NOTE: some of these details are obtained from third party information.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5759

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web script or HTML via the name parameter in an updaterecord action to index.php in the 08_Files module. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5758

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in PHParanoid before 0.5 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors related to private messages.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2008-5757

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in textarea/index.php in Textpattern (aka Txp CMS) 4.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Body parameter in an article action. NOTE: some of these details are obtained from third party information.

Cross-Site Scripting (XSS)
WAF: High

CVE-2008-5752

MEDIUM
4.30 CVSS 2.0

Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information.

Path Traversal
WAF: High

CVE-2008-5751

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to execute arbitrary SQL commands via the id parameter in a directory action.

SQL Injection
WAF: High

CVE-2008-5750

MEDIUM
6.80 CVSS 2.0

Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.

Code Injection
WAF: Medium

CVE-2008-5749

MEDIUM
6.80 CVSS 2.0

Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission.

Code Injection
WAF: Medium

CVE-2008-5748

HIGH
8.10 CVSS 3.1

Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.

Path Traversal
WAF: High
Page 1 of 63 (3144 CVEs)