2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-6597——Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to injec...
CVE-2008-6596——SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL comma...
CVE-2008-6595——SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQ...
CVE-2008-6594——SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL com...
CVE-2008-6593——SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers ...
CVE-2008-6592——thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remo...
CVE-2008-6591——LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create ...
CVE-2008-6590——Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite v...
CVE-2008-6589——Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly S...
CVE-2008-6588——Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers t...
CVE-2008-6587——Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, all...
CVE-2008-6586——Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attack...
CVE-2008-6585——Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack t...
CVE-2008-6584——html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file cont...
CVE-2008-6583——Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2008-6582——SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th...
CVE-2008-6581——login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t...
CVE-2008-6580——The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont...
CVE-2008-6579——Nortel Communication Server 1000 4.50.x allows remote attackers to obtain Web application structure via unknown vectors ...
CVE-2008-6578——Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitr...
CVE-2008-6577——Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspe...
CVE-2008-6576——Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 ...
CVE-2008-6575——Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4....
CVE-2008-6574——Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote at...
CVE-2008-6573——Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, ...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now