NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6007 | CVE-2008-6276 | Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value. | 2 | 6.5 | Medium | 2017-01-03 | 2011-01-20 | View | |
| 6263 | CVE-2008-6532 | Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 6519 | CVE-2008-6788 | SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php. | 2 | 5.1 | Medium | 2017-01-03 | 2009-05-05 | View | |
| 6775 | CVE-2008-7044 | SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-24 | View | |
| 7031 | CVE-2008-7310 | Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model"s attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability. | 2 | 5 | Medium | 2017-01-03 | 2012-04-05 | View |
Page 14960 of 17672, showing 5 records out of 88360 total, starting on record 74796, ending on 74800