NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
2891 | CVE-2008-2997 | Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to inject arbitrary web script or HTML via the subject parameter in a postnewsubmit (aka create new thread) action. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
2892 | CVE-2008-2998 | Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-09-09 | View | |
2893 | CVE-2008-2999 | Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-09-09 | View | |
2894 | CVE-2008-3000 | The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions. | 2 | 6.8 | Medium | 2017-01-03 | 2009-09-09 | View | |
2895 | CVE-2008-3001 | The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions. | 2 | 9.3 | High | 2017-01-03 | 2009-09-09 | View |
Page 579 of 17672, showing 5 records out of 88360 total, starting on record 2891, ending on 2895