2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-5866——The Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 has public as its default SNMP read/write community, which ma...
CVE-2008-5077——OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remo...
CVE-2008-5865——SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f...
CVE-2008-5864——SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System ...
CVE-2008-5863——SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote a...
CVE-2008-5862——Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitra...
CVE-2008-5861——Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via di...
CVE-2008-5860——Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is...
CVE-2008-5859——SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magi...
CVE-2008-5858——Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbi...
CVE-2008-5857——The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privile...
CVE-2008-5856——Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary...
CVE-2008-5855——myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which a...
CVE-2008-5854——Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attacker...
CVE-2008-5853——Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with i...
CVE-2008-5852——Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remot...
CVE-2008-5851——SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary S...
CVE-2008-5850——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate was originally recorded fo...
CVE-2008-5849——Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to ...
CVE-2008-5848——The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtai...
CVE-2008-5847——Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent atta...
CVE-2008-5846——Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass int...
CVE-2008-5845——Multiple cross-site scripting (XSS) vulnerabilities in Six Apart Movable Type (MT) before 4.23 allow remote attackers to...
CVE-2008-5844——PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes...
CVE-2008-5843——Multiple untrusted search path vulnerabilities in pdfjam allow local users to gain privileges via a Trojan horse program...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now