Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0258

Published Jan 15, 2008

Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the mes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0259

Published Jan 15, 2008

Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0260

Published Jan 15, 2008

minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0261

Published Jan 15, 2008

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0262

Published Jan 15, 2008

SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0263

Published Jan 15, 2008

The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0264

Published Jan 15, 2008

Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0265

Published Jan 15, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0266

Published Jan 15, 2008

Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administra…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0267

Published Jan 15, 2008

Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0268

Published Jan 15, 2008

Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0269

Published Jan 15, 2008

Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0270

Published Jan 15, 2008

SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0271

Published Jan 15, 2008

The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0272

Published Jan 15, 2008

Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as pr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0273

Published Jan 15, 2008

Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0274

Published Jan 15, 2008

Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML v…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0275

Published Jan 15, 2008

The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow rem…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0276

Published Jan 15, 2008

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0277

Published Jan 15, 2008

Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0278

Published Jan 15, 2008

SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window actio…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0279

Published Jan 15, 2008

SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter. NOTE: the catego…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0242

Published Jan 12, 2008

Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0243

Published Jan 12, 2008

Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 5,401-5,425 of 5,632 CVEsPage 217 of 226