Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0501

Published Jan 30, 2008

Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6694

Published Jan 29, 2008

The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a denial of service (crash) via u…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0468

Published Jan 29, 2008

SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0469

Published Jan 29, 2008

SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a ne…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0471

Published Jan 29, 2008

Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0472

Published Jan 29, 2008

Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0473

Published Jan 29, 2008

RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0474

Published Jan 29, 2008

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0475

Published Jan 29, 2008

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0476

Published Jan 29, 2008

ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0477

Published Jan 29, 2008

Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0478

Published Jan 29, 2008

Directory traversal vulnerability in index.php in SetCMS 3.6.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set parameter, as dem…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0479

Published Jan 29, 2008

Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0480

Published Jan 29, 2008

Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0481

Published Jan 29, 2008

Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a ...…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0174

Published Jan 29, 2008

GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0175

Published Jan 29, 2008

Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote attackers to execute arbitrary code by uploading a file with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0176

Published Jan 29, 2008

Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0387

Published Jan 29, 2008

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers to execute arbitrary code via c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0467

Published Jan 29, 2008

Stack-based buffer overflow in Firebird before 2.0.4, and 2.1.x before 2.1.0 RC1, might allow remote attackers to execute arbitrary code via a long username.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0405

Published Jan 29, 2008

Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) fi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,176-5,200 of 5,632 CVEsPage 208 of 226