NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
4001  CVE-2008-4145  SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter.    6.8  Medium  2017-01-03  2011-03-07  View
4002  CVE-2008-4146  Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.    Medium  2017-01-03  2011-03-07  View
4003  CVE-2008-4147  Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an attached file that has a modified Content-Type.    4.3  Medium  2017-01-03  2009-03-17  View
4004  CVE-2008-4148  SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API.    7.5  High  2017-01-03  2009-08-19  View
4005  CVE-2008-4149  Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link page header" field.    4.3  Medium  2017-01-03  2009-03-17  View

Page 801 of 17672, showing 5 records out of 88360 total, starting on record 4001, ending on 4005

Actions