Show filters
488 Total Results
Displaying 321-330 of 488
Sort by:
Attacker Value
Unknown

CVE-2008-6275

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
0
Attacker Value
Unknown

CVE-2008-6229

Disclosure Date: February 20, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.
0
Attacker Value
Unknown

CVE-2008-6169

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."
0
Attacker Value
Unknown

CVE-2008-6170

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
0
Attacker Value
Unknown

CVE-2008-6171

Disclosure Date: February 19, 2009 (last updated October 04, 2023)
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
0
Attacker Value
Unknown

CVE-2008-6160

Disclosure Date: February 18, 2009 (last updated October 04, 2023)
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-0603

Disclosure Date: February 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6134

Disclosure Date: February 14, 2009 (last updated October 04, 2023)
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6136

Disclosure Date: February 14, 2009 (last updated October 04, 2023)
Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors.
0
Attacker Value
Unknown

CVE-2008-6135

Disclosure Date: February 14, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0