2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-3312Directory traversal vulnerability in lemon_includes/FCKeditor/editor/filemanager/browser/browser.php in Lemon CMS 1.10 a...
CVE-2008-3311PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arb...
CVE-2008-3310SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands ...
CVE-2008-3309SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S...
CVE-2008-3308PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals...
CVE-2008-3320admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrat...
CVE-2008-3306SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrar...
CVE-2008-3305Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to ...
CVE-2008-3322admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative...
CVE-2008-3321admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrati...
CVE-2008-3295Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject...
CVE-2008-3303admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication a...
CVE-2008-3302SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut...
CVE-2008-3301Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inje...
CVE-2008-3300AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa...
CVE-2008-3299eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng c...
CVE-2008-3304BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo...
CVE-2008-3298SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administr...
CVE-2008-3297Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL ...
CVE-2008-3296Directory traversal vulnerability in modules/system/admin.php in XOOPS 2.0.18 1 allows remote attackers to include and e...
CVE-2008-3292constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by se...
CVE-2008-3294src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-co...
CVE-2008-3293Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the ...
CVE-2008-3291SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execut...
CVE-2008-3290retroclient.exe in EMC Dantz Retrospect Backup Client 7.5.116 allows remote attackers to cause a denial of service (daem...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now