2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-6739——Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem...
CVE-2008-6738——MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce...
CVE-2008-6737——Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by send...
CVE-2008-6736——Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) ad...
CVE-2008-6735——Directory traversal vulnerability in qc/index.php in ThaiQuickCart 3 allows remote attackers to read arbitrary files via...
CVE-2008-6734——Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ...
CVE-2008-6733——Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote atta...
CVE-2008-6732——Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers ...
CVE-2008-6731——Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb...
CVE-2008-6730——Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc ...
CVE-2008-6729——Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att...
CVE-2008-6728——SQL injection vulnerability in the Sections module in PHP-Nuke, probably before 8.0, allows remote attackers to execute ...
CVE-2008-6727——Cross-site scripting (XSS) vulnerability in Ultimate PHP Board (UPB) 2.2.2, 2.2.1, and earlier 2.x versions allows remot...
CVE-2008-5518——Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1...
CVE-2008-6726——Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t...
CVE-2008-6725——Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command...
CVE-2008-6724——Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web...
CVE-2008-1107——Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.4...
CVE-2008-5259——Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute a...
CVE-2008-4830——Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 P...
CVE-2008-6723——TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by...
CVE-2008-6722——Novell Access Manager 3 SP4 does not properly expire X.509 certificate sessions, which allows physically proximate attac...
CVE-2008-6721——SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman...
CVE-2008-4420——Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in Dyna...
CVE-2008-6720——SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to ...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now