NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5646 | CVE-2008-5915 | An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes. | 2 | 2.1 | Low | 2017-01-03 | 2009-01-23 | View | |
5902 | CVE-2008-6171 | includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header. | 2 | 9.3 | High | 2017-01-03 | 2009-05-14 | View | |
6158 | CVE-2008-6427 | SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-09 | View | |
6414 | CVE-2008-6683 | Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject arbitrary web script or HTML via the r parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-14 | View | |
6670 | CVE-2008-6939 | TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileges by setting the adm cookie to 1 or (2) gain privileges as another user by setting the logged cookie to the target username. | 2 | 7.5 | High | 2017-01-03 | 2009-08-12 | View |
Page 1635 of 17672, showing 5 records out of 88360 total, starting on record 8171, ending on 8175