Show filters
488 Total Results
Displaying 321-330 of 488
Sort by:
Attacker Value
Unknown
CVE-2008-6275
Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
0
Attacker Value
Unknown
CVE-2008-6229
Disclosure Date: February 20, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.
0
Attacker Value
Unknown
CVE-2008-6169
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."
0
Attacker Value
Unknown
CVE-2008-6170
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
0
Attacker Value
Unknown
CVE-2008-6171
Disclosure Date: February 19, 2009 (last updated October 04, 2023)
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
0
Attacker Value
Unknown
CVE-2008-6160
Disclosure Date: February 18, 2009 (last updated October 04, 2023)
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-0603
Disclosure Date: February 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-6134
Disclosure Date: February 14, 2009 (last updated October 04, 2023)
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-6136
Disclosure Date: February 14, 2009 (last updated October 04, 2023)
Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2008-6135
Disclosure Date: February 14, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0