NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6169 | CVE-2008-6438 | SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 3612 | CVE-2008-3747 | The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View | |
| 3101 | CVE-2008-3218 | Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 3102 | CVE-2008-3219 | The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism. | 2 | 5 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 3103 | CVE-2008-3220 | Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View |
Page 3325 of 17672, showing 5 records out of 88360 total, starting on record 16621, ending on 16625