Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0446

Published Jan 25, 2008

SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0447

Published Jan 25, 2008

SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0448

Published Jan 25, 2008

PHP remote file inclusion vulnerability in utils/class_HTTPRetriever.php in phpSearch allows remote attackers to execute arbitrary PHP code via a URL in the libcurlemuinc paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0449

Published Jan 25, 2008

SQL injection vulnerability in paypalresult.asp in VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE:…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0450

Published Jan 25, 2008

Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0451

Published Jan 25, 2008

Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) siteadmin/article-edit.php; a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0452

Published Jan 25, 2008

Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via directory traversal sequences in the cat parameter in a view…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0422

Published Jan 23, 2008

SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0423

Published Jan 23, 2008

Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code via a URL in the MY_CONF[classRoot] parameter to (1) inc.s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0424

Published Jan 23, 2008

SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary SQL commands via the month parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0425

Published Jan 23, 2008

Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0426

Published Jan 23, 2008

Multiple cross-site scripting (XSS) vulnerabilities in submit.php in PacerCMS before 0.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) head…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0427

Published Jan 23, 2008

Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0428

Published Jan 23, 2008

Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0429

Published Jan 23, 2008

SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0430

Published Jan 23, 2008

SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0431

Published Jan 23, 2008

Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName param…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0432

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0433

Published Jan 23, 2008

PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0434

Published Jan 23, 2008

Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0435

Published Jan 23, 2008

Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpre…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0436

Published Jan 23, 2008

Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote attackers to inject arbitrary web script or HTML via the target…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0437

Published Jan 23, 2008

Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,226-5,250 of 5,632 CVEsPage 210 of 226