2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-6763login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary...
CVE-2008-6762Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect us...
CVE-2008-6761Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject ar...
CVE-2008-6760ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add an...
CVE-2008-6759ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA pa...
CVE-2008-6758Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote att...
CVE-2008-6757Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attac...
CVE-2008-2438Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attac...
CVE-2008-6756ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the databas...
CVE-2008-6755ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions t...
CVE-2008-6754The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and ...
CVE-2008-6753SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via u...
CVE-2008-6752adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original passw...
CVE-2008-6751Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows...
CVE-2008-6750Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary...
CVE-2008-6749Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabl...
CVE-2008-6748Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the ...
CVE-2008-6747dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain...
CVE-2008-6746Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows rem...
CVE-2008-6745index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg...
CVE-2008-6744Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0....
CVE-2008-6743RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi...
CVE-2008-6742Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo...
CVE-2008-6741SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec...
CVE-2008-6740PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers ...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now