2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-4183 | — | — | 3.2% | Sep 23, 2008 | IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote a... |
| CVE-2008-4182 | — | — | 1.3% | Sep 23, 2008 | Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions befo... |
| CVE-2008-4181 | — | — | 2.8% | Sep 23, 2008 | Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c... |
| CVE-2008-4180 | — | — | 1.2% | Sep 23, 2008 | Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against password... |
| CVE-2008-4179 | — | — | 1.5% | Sep 23, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script o... |
| CVE-2008-4178 | — | — | 3.4% | Sep 23, 2008 | SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D... |
| CVE-2008-4177 | — | — | 1.0% | Sep 23, 2008 | SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c... |
| CVE-2008-4176 | — | — | 1.0% | Sep 23, 2008 | SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL c... |
| CVE-2008-4175 | — | — | 1.1% | Sep 23, 2008 | Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands v... |
| CVE-2008-4174 | — | — | 1.4% | Sep 23, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to i... |
| CVE-2008-3661 | — | — | 2.5% | Sep 23, 2008 | Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause ... |
| CVE-2008-3519 | — | — | 1.6% | Sep 23, 2008 | The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP... |
| CVE-2008-4164 | — | — | 2.2% | Sep 22, 2008 | cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request,... |
| CVE-2008-4163 | — | — | 4.7% | Sep 22, 2008 | Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to ca... |
| CVE-2008-4162 | — | — | 1.1% | Sep 22, 2008 | Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web si... |
| CVE-2008-4161 | — | — | 2.0% | Sep 22, 2008 | SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands... |
| CVE-2008-4160 | — | — | 0.4% | Sep 22, 2008 | Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a de... |
| CVE-2008-3949 | — | — | 0.5% | Sep 22, 2008 | emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during ed... |
| CVE-2008-4173 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran... |
| CVE-2008-4172 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute a... |
| CVE-2008-4171 | — | — | 1.1% | Sep 22, 2008 | SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attack... |
| CVE-2008-4170 | — | — | 1.6% | Sep 22, 2008 | create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob pa... |
| CVE-2008-4169 | — | — | 1.0% | Sep 22, 2008 | SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute ar... |
| CVE-2008-4168 | — | — | 1.1% | Sep 22, 2008 | Cross-site scripting (XSS) vulnerability in verify_login.jsp in Pro2col Stingray FTS allows remote attackers to inject a... |
| CVE-2008-4167 | — | — | 2.6% | Sep 22, 2008 | useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allow... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now