2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-6747dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain...
CVE-2008-6746Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows rem...
CVE-2008-6745index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg...
CVE-2008-6744Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0....
CVE-2008-6743RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi...
CVE-2008-6742Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo...
CVE-2008-6741SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec...
CVE-2008-6740PHP remote file inclusion vulnerability in html/admin/modules/plugin_admin.php in HoMaP-CMS 0.1 allows remote attackers ...
CVE-2008-6739Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem...
CVE-2008-6738MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce...
CVE-2008-6737Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by send...
CVE-2008-6736Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) ad...
CVE-2008-6735Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via...
CVE-2008-6734Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ...
CVE-2008-6733Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote atta...
CVE-2008-6732Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers ...
CVE-2008-6731Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb...
CVE-2008-6730Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc ...
CVE-2008-6729Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att...
CVE-2008-6728SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute ...
CVE-2008-6727Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remot...
CVE-2008-5518Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1...
CVE-2008-6726Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t...
CVE-2008-6725Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command...
CVE-2008-6724Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now