LiveActive security incident?Get immediate response
CVE archive

July 2008

Browse CVE records published in July 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 559 matching CVEs · Page 9 of 12.

Unknown · CVSS Not scored

CVE-2008-2982: Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, a...

Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.

Published Jul 2, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-3033: RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which...

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

Published Jul 7, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-3068: Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, p...

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Published Jul 7, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-2967: Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8...

Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to login.php and the (2) glb_sid parameter to hta/htmlarea.js.php, and allow remote authenticated users to inject arbitrary web script or HTML via an unspecified field in room.php.

Published Jul 2, 2008 · Updated Aug 7, 2024