Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-5807

Published Dec 31, 2008

Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) Testproject Names and (2) Test…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5806

Published Dec 31, 2008

SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5805

Published Dec 31, 2008

SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a dif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5804

Published Dec 31, 2008

SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5803

Published Dec 31, 2008

SQL injection vulnerability in admin/login.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka username field).…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5802

Published Dec 31, 2008

SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5801

Published Dec 31, 2008

Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5799

Published Dec 31, 2008

Cross-site scripting (XSS) vulnerability in the Wir ber uns (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5794

Published Dec 31, 2008

Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5793

Published Dec 31, 2008

Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP cod…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5792

Published Dec 31, 2008

PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL i…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5791

Published Dec 31, 2008

Multiple unspecified vulnerabilities in PrestaShop e-Commerce Solution before 1.1 Beta 2 (aka 1.1.0.1) have unknown impact and attack vectors, related to the (1) bankwire module,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5790

Published Dec 31, 2008

Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla! allow remote attackers to execute arbitrary PHP code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5789

Published Dec 31, 2008

Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5788

Published Dec 31, 2008

SQL injection vulnerability in index.php in Domain Seller Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5787

Published Dec 31, 2008

Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, in conjunction…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5786

Published Dec 31, 2008

Cross-site scripting (XSS) vulnerability in the Silva Find extension 1.1.5 and earlier in Silva 1.x before 1.6.3.2, Silva 2.0 before 2.0.12.2, and Silva 2.1 before 2.1.0.2 allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5785

Published Dec 31, 2008

SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5783

Published Dec 31, 2008

admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 5,632 CVEsPage 1 of 226