2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4183IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote a...
CVE-2008-4182Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions befo...
CVE-2008-4181Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c...
CVE-2008-4180Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against password...
CVE-2008-4179Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script o...
CVE-2008-4178SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D...
CVE-2008-4177SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c...
CVE-2008-4176SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL c...
CVE-2008-4175Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands v...
CVE-2008-4174Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to i...
CVE-2008-3661Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause ...
CVE-2008-3519The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP...
CVE-2008-4164cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request,...
CVE-2008-4163Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to ca...
CVE-2008-4162Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web si...
CVE-2008-4161SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands...
CVE-2008-4160Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a de...
CVE-2008-3949emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during ed...
CVE-2008-4173SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran...
CVE-2008-4172SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute a...
CVE-2008-4171SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attack...
CVE-2008-4170create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob pa...
CVE-2008-4169SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute ar...
CVE-2008-4168Cross-site scripting (XSS) vulnerability in verify_login.jsp in Pro2col Stingray FTS allows remote attackers to inject a...
CVE-2008-4167useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allow...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now