LiveActive security incident?Get immediate response
CVE archive

April 2008

Browse CVE records published in April 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 659 matching CVEs · Page 3 of 14.

Unknown · CVSS Not scored

CVE-2008-6717: U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin...

U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php.

Published Apr 13, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6666: Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitr...

Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown.

Published Apr 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6673: asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, wh...

asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact address, via the saveAdmin; and (3) modify the site design via the saveDesign action.

Published Apr 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6675: Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject a...

Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3) SB_feedback parameters in process_send.asp, as reachable through default.asp; (4) paramCode and (5) cColor parameters to picker.asp; and the (6) query string, (7) Referer header, and (8) X-FORWARDED-FOR header to rss.asp.

Published Apr 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6743: RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setti...

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

Published Apr 22, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6659: Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 bef...

Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to Sources/QueryString.php and Sources/Themes.php, as demonstrated by a local .gif file in attachments/ with PHP code that was uploaded through a profile2 action to index.php.

Published Apr 7, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6660: Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attacker...

Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct request. NOTE: some of these details are obtained from third party information.

Published Apr 7, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6614: Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5...

Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field).

Published Apr 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6641: Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to exe...

Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrary SQL commands via the sid parameter to (1) kanal.asp, (2) google.asp, and (3) hakk.asp in yonet/; and allow remote attackers to execute arbitrary SQL commands via the (4) username or (5) password fields to yonet/default.asp.

Published Apr 7, 2009 · Updated Aug 7, 2024