2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-6518Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users...
CVE-2008-6517SQL injection vulnerability in NewsHOWLER 1.03 Beta allows remote attackers to execute arbitrary SQL commands via the ne...
CVE-2008-6516Multiple directory traversal vulnerabilities in phpKF-Portal 1.10 allow remote attackers to include arbitrary files via ...
CVE-2008-6515Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows...
CVE-2008-6514The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access...
CVE-2008-6513Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to...
CVE-2008-6512Cross-domain vulnerability in the WorkerPool API in Google Gears before 0.5.4.2 allows remote attackers to bypass the Sa...
CVE-2008-6511Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb...
CVE-2008-6510Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote ...
CVE-2008-6509SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execut...
CVE-2008-6508Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem...
CVE-2008-6507Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors rel...
CVE-2008-6506Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-...
CVE-2008-6505Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote at...
CVE-2008-6504ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and othe...
CVE-2008-6503Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web...
CVE-2008-6502Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local...
CVE-2008-6501Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject...
CVE-2008-6500Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrar...
CVE-2008-6499security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re...
CVE-2008-6498Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to ...
CVE-2008-6497The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTT...
CVE-2008-6496Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT ...
CVE-2008-6495Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yap...
CVE-2008-6494ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now