2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-6605Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 17...
CVE-2008-6604Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbi...
CVE-2008-6603MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote...
CVE-2008-6602Unspecified vulnerability in Download Center Lite before 2.1 has unknown impact and attack vectors related to "A minor s...
CVE-2008-6601Unspecified vulnerability in Epona 1.5rc3 allows remote attackers to obtain the real IP address of users via unknown vec...
CVE-2008-6600Cross-site scripting (XSS) vulnerability in the search feature in XMLPortal 3.0 allows remote attackers to inject arbitr...
CVE-2008-6599cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which all...
CVE-2008-6598Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
CVE-2008-6597Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to injec...
CVE-2008-6596SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL comma...
CVE-2008-6595SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQ...
CVE-2008-6594SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL com...
CVE-2008-6593SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers ...
CVE-2008-6592thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remo...
CVE-2008-6591LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create ...
CVE-2008-6590Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite v...
CVE-2008-6589Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly S...
CVE-2008-6588Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers t...
CVE-2008-6587Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, all...
CVE-2008-6586Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attack...
CVE-2008-6585Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack t...
CVE-2008-6584html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file cont...
CVE-2008-6583Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2008-6582SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th...
CVE-2008-6581login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now