NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6641 | CVE-2008-6910 | Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
6642 | CVE-2008-6911 | SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-07 | View | |
6643 | CVE-2008-6912 | Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php. | 2 | 7.5 | High | 2017-01-03 | 2009-08-13 | View | |
6644 | CVE-2008-6913 | Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-13 | View | |
6645 | CVE-2008-6914 | Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-10 | View |
Page 1329 of 17672, showing 5 records out of 88360 total, starting on record 6641, ending on 6645