2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4790The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restriction...
CVE-2008-4789The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to byp...
CVE-2008-4788Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote...
CVE-2008-4787Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a ...
CVE-2008-4786SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary...
CVE-2008-4785SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack...
CVE-2008-4784aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a c...
CVE-2008-4783tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login coo...
CVE-2008-4782SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at...
CVE-2008-4781Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary...
CVE-2008-4780Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote at...
CVE-2008-4779Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary ...
CVE-2008-4778SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL co...
CVE-2008-4777SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attack...
CVE-2008-4776libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large l...
CVE-2008-4775Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11....
CVE-2008-4774Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web sc...
CVE-2008-4773Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via...
CVE-2008-4772SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via t...
CVE-2008-4771Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a...
CVE-2008-4769Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and ...
CVE-2008-4768SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom paramet...
CVE-2008-4767Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitr...
CVE-2008-4766SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQ...
CVE-2008-4765SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now