NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6007  CVE-2008-6276  Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.    6.5  Medium  2017-01-03  2011-01-20  View
6263  CVE-2008-6532  Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.    6.8  Medium  2017-01-03  2009-04-25  View
6519  CVE-2008-6788  SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.    5.1  Medium  2017-01-03  2009-05-05  View
6775  CVE-2008-7044  SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.    7.5  High  2017-01-03  2009-08-24  View
7031  CVE-2008-7310  Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model"s attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability.    Medium  2017-01-03  2012-04-05  View

Page 14960 of 17672, showing 5 records out of 88360 total, starting on record 74796, ending on 74800

Actions