NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
6114 | CVE-2008-6383 | SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors. | 2 | 6 | Medium | 2017-01-03 | 2009-05-14 | View | |
6370 | CVE-2008-6639 | Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-07 | View | |
71906 | CVE-2004-1527 | Microsoft Internet Explorer 6.0 SP1 does not properly handle certain character strings in the Path attribute, which can cause it to modify cookies in other domains when the attacker's domain name is within the target's domain name or when wildcard DNS is being used, which allows remote attackers to hijack web sessions. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
6882 | CVE-2008-7151 | Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-09 | View | |
7138 | CVE-2017-5520 | The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions. | 2 | 6.5 | Medium | 2017-01-30 | 2017-01-27 | View |
Page 16612 of 17672, showing 5 records out of 88360 total, starting on record 83056, ending on 83060