NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6008  CVE-2008-6277  SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter.    7.5  High  2017-01-03  2009-08-19  View
6264  CVE-2008-6533  Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.    4.3  Medium  2017-01-03  2009-04-25  View
6520  CVE-2008-6789  SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.    5.1  Medium  2017-01-03  2009-05-13  View
6776  CVE-2008-7045  AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.    6.4  Medium  2017-01-03  2009-08-24  View
7032  CVE-2008-7311  The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file.    Medium  2017-01-03  2012-04-12  View

Page 2614 of 17672, showing 5 records out of 88360 total, starting on record 13066, ending on 13070

Actions