2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-6771 | — | — | 5.9% | Apr 29, 2009 | YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di... |
| CVE-2008-6770 | — | — | 5.9% | Apr 29, 2009 | YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allo... |
| CVE-2008-6769 | — | — | 4.9% | Apr 29, 2009 | Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to... |
| CVE-2008-6768 | — | — | 4.4% | Apr 29, 2009 | Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute... |
| CVE-2008-6767 | — | — | 4.6% | Apr 28, 2009 | wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly caus... |
| CVE-2008-6766 | — | — | 1.4% | Apr 28, 2009 | cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shop... |
| CVE-2008-6765 | — | — | 2.4% | Apr 28, 2009 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a mo... |
| CVE-2008-6764 | — | — | 1.5% | Apr 28, 2009 | Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbit... |
| CVE-2008-6763 | — | — | 6.5% | Apr 28, 2009 | login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary... |
| CVE-2008-6762 | — | — | 2.1% | Apr 28, 2009 | Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect us... |
| CVE-2008-6761 | — | — | 6.3% | Apr 28, 2009 | Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject ar... |
| CVE-2008-6760 | — | — | 1.7% | Apr 28, 2009 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add an... |
| CVE-2008-6759 | — | — | 1.3% | Apr 28, 2009 | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA pa... |
| CVE-2008-6758 | — | — | 1.0% | Apr 28, 2009 | Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote att... |
| CVE-2008-6757 | — | — | 1.5% | Apr 28, 2009 | Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attac... |
| CVE-2008-2438 | — | — | 11.4% | Apr 28, 2009 | Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attac... |
| CVE-2008-6756 | — | — | 0.3% | Apr 27, 2009 | ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the databas... |
| CVE-2008-6755 | — | — | 1.2% | Apr 27, 2009 | ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions t... |
| CVE-2008-6754 | — | — | 1.0% | Apr 27, 2009 | The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and ... |
| CVE-2008-6753 | — | — | 1.1% | Apr 27, 2009 | SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via u... |
| CVE-2008-6752 | — | — | 6.3% | Apr 24, 2009 | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original passw... |
| CVE-2008-6751 | — | — | 3.6% | Apr 24, 2009 | Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows... |
| CVE-2008-6750 | — | — | 3.5% | Apr 24, 2009 | Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary... |
| CVE-2008-6749 | — | — | 2.0% | Apr 24, 2009 | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabl... |
| CVE-2008-6748 | — | — | 3.7% | Apr 24, 2009 | Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the ... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now