NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
5646  CVE-2008-5915  An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.    2.1  Low  2017-01-03  2009-01-23  View
5902  CVE-2008-6171  includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.    9.3  High  2017-01-03  2009-05-14  View
6158  CVE-2008-6427  SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.    6.8  Medium  2017-01-03  2009-09-09  View
6414  CVE-2008-6683  Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter.    4.3  Medium  2017-01-03  2009-04-14  View
6670  CVE-2008-6939  TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username.    7.5  High  2017-01-03  2009-08-12  View

Page 1635 of 17672, showing 5 records out of 88360 total, starting on record 8171, ending on 8175

Actions