LiveActive security incident?Get immediate response
CVE archive

2008 CVE Archive

Browse CVE records published in 2008 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 7005 matching CVEs · Page 17 of 141.

Unknown · CVSS Not scored

CVE-2008-6773: Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows...

Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary PHP code into user/internettoolbar/index.php via the (1) fav1_url, (2) fav1_name, (3) fav2_url, (4) fav2_name, (5) fav3_url, (6) fav3_name, (7) fav4_url, (8) fav4_name, (9) fav5_url, or (10) fav5_name parameters.

Published Apr 29, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6709: Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4....

Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters."

Published Apr 10, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6706: Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES)...

Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts "subscriber table passwords," (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts "subscriber table passwords."

Published Apr 10, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6708: Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4....

Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain root privileges via unknown vectors related to configuration of "data viewing or restoring parameters."

Published Apr 10, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6736: Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attack...

Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

Published Apr 21, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6717: U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin...

U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory, which allows remote attackers to have an unspecified impact via a direct request to (1) adminstart.php, (2) admineventtype.php, (3) admineventdetails.php, (4) admineventlist.php, (5) adminuserslist.php, (6) adminleaderslist.php, (7) admindatabase.php, and possibly (8) index.php.

Published Apr 13, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6666: Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitr...

Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown.

Published Apr 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6673: asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, wh...

asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact address, via the saveAdmin; and (3) modify the site design via the saveDesign action.

Published Apr 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6675: Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject a...

Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3) SB_feedback parameters in process_send.asp, as reachable through default.asp; (4) paramCode and (5) cColor parameters to picker.asp; and the (6) query string, (7) Referer header, and (8) X-FORWARDED-FOR header to rss.asp.

Published Apr 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6743: RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setti...

RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

Published Apr 22, 2009 · Updated Aug 7, 2024