2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-6739Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem...
CVE-2008-6738MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce...
CVE-2008-6737Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by send...
CVE-2008-6736Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) ad...
CVE-2008-6735Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via...
CVE-2008-6734Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ...
CVE-2008-6733Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote atta...
CVE-2008-6732Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers ...
CVE-2008-6731Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb...
CVE-2008-6730Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc ...
CVE-2008-6729Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att...
CVE-2008-6728SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute ...
CVE-2008-6727Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remot...
CVE-2008-5518Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1...
CVE-2008-6726Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t...
CVE-2008-6725Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command...
CVE-2008-6724Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web...
CVE-2008-1107Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.4...
CVE-2008-5259Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute a...
CVE-2008-4830Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 P...
CVE-2008-6723TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by...
CVE-2008-6722Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attac...
CVE-2008-6721SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman...
CVE-2008-4420Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in Dyna...
CVE-2008-6720SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to ...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now