Show filters
488 Total Results
Displaying 361-370 of 488
Sort by:
Attacker Value
Unknown
CVE-2008-3500
Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.
0
Attacker Value
Unknown
CVE-2008-3223
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
0
Attacker Value
Unknown
CVE-2008-3221
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
0
Attacker Value
Unknown
CVE-2008-3218
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.
0
Attacker Value
Unknown
CVE-2008-3219
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
0
Attacker Value
Unknown
CVE-2008-3222
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-3220
Disclosure Date: July 18, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
0
Attacker Value
Unknown
CVE-2008-3097
Disclosure Date: July 09, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.
0
Attacker Value
Unknown
CVE-2008-3095
Disclosure Date: July 09, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-3091
Disclosure Date: July 09, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to inject arbitrary web script or HTML via unspecified vectors.
0