2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-6605——Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 17...
CVE-2008-6604——Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbi...
CVE-2008-6603——MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote...
CVE-2008-6602——Unspecified vulnerability in Download Center Lite before 2.1 has unknown impact and attack vectors related to "A minor s...
CVE-2008-6601——Unspecified vulnerability in Epona 1.5rc3 allows remote attackers to obtain the real IP address of users via unknown vec...
CVE-2008-6600——Cross-site scripting (XSS) vulnerability in the search feature in XMLPortal 3.0 allows remote attackers to inject arbitr...
CVE-2008-6599——cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which all...
CVE-2008-6598——Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
CVE-2008-6597——Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to injec...
CVE-2008-6596——SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL comma...
CVE-2008-6595——SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQ...
CVE-2008-6594——SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL com...
CVE-2008-6593——SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers ...
CVE-2008-6592——thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remo...
CVE-2008-6591——LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create ...
CVE-2008-6590——Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite v...
CVE-2008-6589——Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly S...
CVE-2008-6588——Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers t...
CVE-2008-6587——Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, all...
CVE-2008-6586——Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attack...
CVE-2008-6585——Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack t...
CVE-2008-6584——html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file cont...
CVE-2008-6583——Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2008-6582——SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th...
CVE-2008-6581——login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now