NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
3101  CVE-2008-3218  Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.    4.3  Medium  2017-01-03  2009-08-19  View
3102  CVE-2008-3219  The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.    Medium  2017-01-03  2009-08-19  View
3103  CVE-2008-3220  Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."    6.8  Medium  2017-01-03  2009-08-19  View
3104  CVE-2008-3221  Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.    4.3  Medium  2017-01-03  2009-08-19  View
3105  CVE-2008-3222  Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.    6.8  Medium  2017-01-03  2009-08-19  View

Page 621 of 17672, showing 5 records out of 88360 total, starting on record 3101, ending on 3105

Actions