NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6008 | CVE-2008-6277 | SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to execute arbitrary SQL commands via the subcategory_id parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 6264 | CVE-2008-6533 | Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 6520 | CVE-2008-6789 | SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788. | 2 | 5.1 | Medium | 2017-01-03 | 2009-05-13 | View | |
| 6776 | CVE-2008-7045 | AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php. | 2 | 6.4 | Medium | 2017-01-03 | 2009-08-24 | View | |
| 7032 | CVE-2008-7311 | The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file. | 2 | 5 | Medium | 2017-01-03 | 2012-04-12 | View |
Page 2614 of 17672, showing 5 records out of 88360 total, starting on record 13066, ending on 13070