2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-6747——dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain...
CVE-2008-6746——Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows rem...
CVE-2008-6745——index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg...
CVE-2008-6744——Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0....
CVE-2008-6743——RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi...
CVE-2008-6742——Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo...
CVE-2008-6741——SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec...
CVE-2008-6740——PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers ...
CVE-2008-6739——Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem...
CVE-2008-6738——MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce...
CVE-2008-6737——Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by send...
CVE-2008-6736——Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) ad...
CVE-2008-6735——Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via...
CVE-2008-6734——Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ...
CVE-2008-6733——Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote atta...
CVE-2008-6732——Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers ...
CVE-2008-6731——Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb...
CVE-2008-6730——Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc ...
CVE-2008-6729——Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att...
CVE-2008-6728——SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute ...
CVE-2008-6727——Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remot...
CVE-2008-5518——Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1...
CVE-2008-6726——Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t...
CVE-2008-6725——Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command...
CVE-2008-6724——Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now