2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-4173 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran... |
| CVE-2008-4172 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute a... |
| CVE-2008-4171 | — | — | 1.1% | Sep 22, 2008 | SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attack... |
| CVE-2008-4170 | — | — | 1.6% | Sep 22, 2008 | create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob pa... |
| CVE-2008-4169 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute ar... |
| CVE-2008-4168 | — | — | 1.1% | Sep 22, 2008 | Cross-site scripting (XSS) vulnerability in verify_login.jsp in Pro2col Stingray FTS allows remote attackers to inject a... |
| CVE-2008-4167 | — | — | 2.6% | Sep 22, 2008 | useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allow... |
| CVE-2008-4166 | — | — | 2.2% | Sep 22, 2008 | Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a d... |
| CVE-2008-4165 | — | — | 1.0% | Sep 22, 2008 | admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows l... |
| CVE-2008-4159 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitra... |
| CVE-2008-4158 | — | — | 2.0% | Sep 22, 2008 | Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and ex... |
| CVE-2008-4157 | — | — | 5.6% | Sep 22, 2008 | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL c... |
| CVE-2008-4156 | — | — | 0.9% | Sep 19, 2008 | SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allow... |
| CVE-2008-4155 | — | — | 3.0% | Sep 19, 2008 | Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire... |
| CVE-2008-4154 | — | — | 1.0% | Sep 19, 2008 | SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the... |
| CVE-2008-4135 | — | — | 4.4% | Sep 19, 2008 | Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause... |
| CVE-2008-4134 | — | — | 7.7% | Sep 19, 2008 | PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other ver... |
| CVE-2008-4133 | — | — | 4.2% | Sep 19, 2008 | The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with la... |
| CVE-2008-4132 | — | — | 4.1% | Sep 19, 2008 | Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.2... |
| CVE-2008-4131 | — | — | 0.8% | Sep 19, 2008 | Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors relate... |
| CVE-2008-4130 | — | — | 1.6% | Sep 18, 2008 | Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web scr... |
| CVE-2008-4129 | — | — | 1.8% | Sep 18, 2008 | Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allow... |
| CVE-2008-3662 | — | — | 1.8% | Sep 18, 2008 | Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, whi... |
| CVE-2008-2470 | — | — | 5.5% | Sep 18, 2008 | The InstallShield Update Service Agent ActiveX control in isusweb.dll allows remote attackers to cause a denial of servi... |
| CVE-2008-4127 | — | — | 16.4% | Sep 18, 2008 | Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers ... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now