NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
58294 | CVE-2007-6299 | Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules. | 2 | 7.5 | High | 2017-01-07 | 2008-09-05 | View | |
59574 | CVE-2006-0844 | Leif M. Wright"s Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60598 | CVE-2006-1893 | Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
62902 | CVE-2006-4263 | Multiple PHP remote file inclusion vulnerabilities in the Product Scroller Module and other modules in mambo-phpshop (com_phpshop) for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) mod_phpshop.php, (2) mod_phpshop_allinone.php, (3) mod_phpshop_cart.php, (4) mod_phpshop_featureprod.php, (5) mod_phpshop_latestprod.php, (6) mod_product_categories.php, (7) mod_productscroller.php, and (8) mosproductsnap.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
63158 | CVE-2006-4525 | Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 1218 of 17672, showing 5 records out of 88360 total, starting on record 6086, ending on 6090