LiveActive security incident?Get immediate response
CVE archive

2008 CVE Archive

Browse CVE records published in 2008 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 7005 matching CVEs · Page 14 of 141.

Unknown · CVSS Not scored

CVE-2008-6878: Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and ea...

Directory traversal vulnerability in admin/includes/languages/english.php in Zen Cart 1.3.8a, 1.3.8, and earlier, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _SESSION[language] parameter. NOTE: the vendor disputes this issue, stating "at worst, the use of this vulnerability will reveal some local file paths.

Published Jul 27, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6841: PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Databas...

PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to classes/DBQ/admin/common.class.php.

Published Jul 1, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6839: Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attacker...

Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) login.php and (b) index.php, and the (3) dir and (4) id parameters to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Jun 27, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6844: The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before...

The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote attackers to gain privileges as other users via modified ContentObjectAttribute_data_user_login_30, ContentObjectAttribute_data_user_password_30, and other parameters.

Published Jul 2, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6840: Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arb...

Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[pear_dir] parameter to (a) Mail/RFC822.php, (b) Net/Socket.php, (c) XML/Parser.php, (d) XML/Tree.php, (e) Mail/mimeDecode.php, (f) Console/Getopt.php, (g) System.php, (h) Log.php, and (i) File.php in includes/pear/; the CONFIG[pear_dir] parameter to (j) includes/prepend.php, and (k) includes/cachedConfig.php; and the (2) CONFIG[includes] parameter to (l) prepend.php and (m) email.list.search.php in includes/. NOTE: the CONFIG[pear_dir] parameter to includes/mailaccess/pop3.php is already covered by CVE-2006-2666.

Published Jul 1, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6830: The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not prope...

The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface session. NOTE: the attacker must also have valid credentials to the Web Interface.

Published Jun 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6831: Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote...

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter in the ViewProfile page or (2) returnUrl parameter in a form, as demonstrated using secure/AddComment!default.jspa (aka "Add Comment").

Published Jun 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6814: Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1...

Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg content type, then accessing this file via a direct request to the file in components/com_simpleboard/, a different vulnerability than CVE-2006-3528.

Published May 28, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6846: Multiple stack-based buffer overflows in avast!

Multiple stack-based buffer overflows in avast! Linux Home Edition 1.0.5, 1.0.5-1, and 1.0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via a malformed (1) ISO or (2) RPM file.

Published Jul 2, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6807: PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to exe...

PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrary PHP code via a URL in the xml_dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the lib_dir vector is already covered by CVE-2006-6630.

Published May 12, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6834: Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to in...

Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the s parameter to code/commupdate.php in a count action or (2) the heads parameter to code/newsheads.php. NOTE: the blog.php vector is already covered by CVE-2008-3164.

Published Jun 22, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6823: Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP...

Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.

Published Jun 4, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6822: Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka I...

Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by an upload with an image/jpeg content type. NOTE: some of these details are obtained from third party information.

Published Jun 4, 2009 · Updated Aug 7, 2024