2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-6597Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to injec...
CVE-2008-6596SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL comma...
CVE-2008-6595SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQ...
CVE-2008-6594SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL com...
CVE-2008-6593SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers ...
CVE-2008-6592thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remo...
CVE-2008-6591LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create ...
CVE-2008-6590Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite v...
CVE-2008-6589Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly S...
CVE-2008-6588Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers t...
CVE-2008-6587Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, all...
CVE-2008-6586Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attack...
CVE-2008-6585Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack t...
CVE-2008-6584html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file cont...
CVE-2008-6583Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2008-6582SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th...
CVE-2008-6581login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t...
CVE-2008-6580The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont...
CVE-2008-6579Nortel Communication Server 1000 4.50.x allows remote attackers to obtain Web application structure via unknown vectors ...
CVE-2008-6578Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitr...
CVE-2008-6577Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspe...
CVE-2008-6576Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 ...
CVE-2008-6575Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4....
CVE-2008-6574Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote at...
CVE-2008-6573Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, ...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now