LiveActive security incident?Get immediate response
CVE archive

February 2008

Browse CVE records published in February 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 836 matching CVEs · Page 5 of 17.

Unknown · CVSS Not scored

CVE-2008-6127: Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers...

Multiple cross-site scripting (XSS) vulnerabilities in moziloCMS 1.10.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) query parameters to (a) index.php, (3) cat and (4) file parameters to (b) download.php, (5) gal parameter to gallery.php, and the (6) URL to admin/login.php.

Published Feb 13, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6119: Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows...

Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 11, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6196: Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers...

Multiple PHP remote file inclusion vulnerabilities in Philippe CROCHAT EasySite 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the EASYSITE_BASE parameter to (1) browser.php, (2) image_editor.php and (3) skin_chooser.php in configuration/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 20, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6178: Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php i...

Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094. NOTE: some of these details are obtained from third party information.

Published Feb 19, 2009 · Updated Aug 7, 2024