2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4790——The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restriction...
CVE-2008-4789——The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to byp...
CVE-2008-4788——Microsoft Internet Explorer 6 omits high-bit URL-encoded characters when displaying the address bar, which allows remote...
CVE-2008-4787——Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a ...
CVE-2008-4786——SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary...
CVE-2008-4785——SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack...
CVE-2008-4784——aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a c...
CVE-2008-4783——tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login coo...
CVE-2008-4782——SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at...
CVE-2008-4781——Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary...
CVE-2008-4780——Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote at...
CVE-2008-4779——Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary ...
CVE-2008-4778——SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL co...
CVE-2008-4777——SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attack...
CVE-2008-4776——libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large l...
CVE-2008-4775——Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11....
CVE-2008-4774——Cross-site scripting (XSS) vulnerability in main/main.php in QuestCMS allows remote attackers to inject arbitrary web sc...
CVE-2008-4773——Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via...
CVE-2008-4772——SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via t...
CVE-2008-4771——Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a...
CVE-2008-4769——Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and ...
CVE-2008-4768——SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom paramet...
CVE-2008-4767——Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitr...
CVE-2008-4766——SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQ...
CVE-2008-4765——SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now