NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6263 | CVE-2008-6532 | Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 6264 | CVE-2008-6533 | Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 6281 | CVE-2008-6550 | Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-25 | View | |
| 48687 | CVE-2009-1411 | SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php. | 2 | 7.5 | High | 2017-01-07 | 2009-04-27 | View | |
| 48709 | CVE-2009-1433 | SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-04-27 | View |
Page 3014 of 17672, showing 5 records out of 88360 total, starting on record 15066, ending on 15070