NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6636 | CVE-2008-6905 | Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to hijack the authentication of administrators for requests that delete (1) categories or (2) groups; (3) ban users; or (4) delete users via the admin page. | 2 | 6 | Medium | 2017-01-03 | 2009-08-06 | View | |
6637 | CVE-2008-6906 | Cross-site scripting (XSS) vulnerability in index.php in BabbleBoard 1.1.6 allows remote attackers to inject arbitrary web script or HTML via the username. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-06 | View | |
6638 | CVE-2008-6907 | Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, as accessible from a form generated by index.php. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-06 | View | |
6639 | CVE-2008-6908 | Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges. | 2 | 7.5 | High | 2017-01-03 | 2009-08-07 | View | |
6640 | CVE-2008-6909 | Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-19 | View |
Page 1328 of 17672, showing 5 records out of 88360 total, starting on record 6636, ending on 6640