Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0325

Published Jan 17, 2008

SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0326

Published Jan 17, 2008

SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0327

Published Jan 17, 2008

SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0328

Published Jan 17, 2008

SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0329

Published Jan 17, 2008

LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to acce…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0330

Published Jan 17, 2008

Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sen…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0331

Published Jan 17, 2008

Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0332

Published Jan 17, 2008

Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0333

Published Jan 17, 2008

Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0334

Published Jan 17, 2008

Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0335

Published Jan 17, 2008

Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0336

Published Jan 17, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0337

Published Jan 17, 2008

Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0338

Published Jan 17, 2008

Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary dir…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0324

Published Jan 17, 2008

Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, w…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6685

Published Jan 17, 2008

Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6686

Published Jan 17, 2008

The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6687

Published Jan 17, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6688

Published Jan 17, 2008

Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the sto…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6689

Published Jan 17, 2008

Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core applicati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,326-5,350 of 5,632 CVEsPage 214 of 226