| Name |
Description |
| CVE-2017-6919 |
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access
bypass by authenticated users if the RESTful Web Services (rest) module
is enabled and the site allows PATCH requests.
|
| CVE-2017-6381 |
A 3rd party development library including with Drupal 8 development
dependencies is vulnerable to remote code execution. This is mitigated
by the default .htaccess protection against PHP execution, and the
fact that Composer development dependencies aren't normal installed.
You might be vulnerable to this if you are running a version of Drupal
before 8.2.2. To be sure you aren't vulnerable, you can remove the
<siteroot>/vendor/phpunit directory from your production deployments
|
| CVE-2017-6379 |
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include
protection for CSRF. This would allow an attacker to disable some
blocks on a site. This issue is mitigated by the fact that users would
have to know the block ID.
|
| CVE-2017-6377 |
When adding a private file via the editor in Drupal 8.2.x before
8.2.7, the editor will not correctly check access for the file being
attached, resulting in an access bypass.
|
| CVE-2016-9452 |
The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote
attackers to cause a denial of service via a crafted URL.
|
| CVE-2016-9451 |
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote
authenticated users to conduct open redirect attacks via unspecified
vectors.
|
| CVE-2016-9450 |
The user password reset form in Drupal 8.x before 8.2.3 allows remote
attackers to conduct cache poisoning attacks by leveraging failure to
specify a correct cache context.
|
| CVE-2016-9449 |
The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3
might allow remote authenticated users to obtain sensitive information
about taxonomy terms by leveraging inconsistent naming of access query
tags.
|
| CVE-2016-7572 |
The system.temporary route in Drupal 8.x before 8.1.10 does not
properly check for "Export configuration" permission, which allows
remote authenticated users to bypass intended access restrictions and
read a full config export via unspecified vectors.
|
| CVE-2016-7571 |
Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10
allows remote attackers to inject arbitrary web script or HTML via
vectors involving an HTTP exception.
|
| CVE-2016-7570 |
Drupal 8.x before 8.1.10 does not properly check for "Administer
comments" permission, which allows remote authenticated users to set
the visibility of comments for arbitrary nodes by leveraging rights to
edit those nodes.
|
| CVE-2016-6212 |
The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views
module in Drupal 8.x before 8.1.3 might allow remote authenticated
users to bypass intended access restrictions and obtain sensitive
Statistics information via unspecified vectors.
|
| CVE-2016-6211 |
The User module in Drupal 7.x before 7.44 allows remote authenticated
users to gain privileges via vectors involving contributed or custom
code that triggers a rebuild of the user profile form.
|
| CVE-2016-3188 |
The _prepopulate_request_walk function in the Prepopulate module
7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify
the (1) actions, (2) container, (3) token, (4) password, (5)
password_confirm, (6) text_format, or (7) markup field type, and
consequently have unspecified impact, via unspecified vectors.
|
| CVE-2016-3187 |
The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote
attackers to modify the REQUEST superglobal array, and consequently
have unspecified impact, via a base64-encoded pp parameter.
|
| CVE-2016-3171 |
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before
5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to
execute arbitrary code via vectors related to session data truncation.
|
| CVE-2016-3170 |
The "have you forgotten your password" links in the User module in
Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to
obtain sensitive username information by leveraging a configuration
that permits using an email address to login and a module that permits
logging in.
|
| CVE-2016-3169 |
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows
remote attackers to gain privileges by leveraging contributed or
custom code that calls the user_save function with an explicit
category and loads all roles into the array.
|
| CVE-2016-3168 |
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might
allow remote attackers to hijack the authentication of site
administrators for requests that download and run files with arbitrary
JSON-encoded content, aka a "reflected file download vulnerability."
|
| CVE-2016-3167 |
Open redirect vulnerability in the drupal_goto function in Drupal 6.x
before 6.38, when used with PHP before 5.4.7, allows remote attackers
to redirect users to arbitrary web sites and conduct phishing attacks
via a double-encoded URL in the "destination" parameter.
|
| CVE-2016-3166 |
CRLF injection vulnerability in the drupal_set_header function in
Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote
attackers to inject arbitrary HTTP headers and conduct HTTP response
splitting attacks by leveraging a module that allows user-submitted
data to appear in HTTP headers.
|
| CVE-2016-3165 |
The Form API in Drupal 6.x before 6.38 ignores access restrictions on
submit buttons, which might allow remote attackers to bypass intended
access restrictions by leveraging permission to submit a form with a
button that has "#access" set to FALSE in the server-side form
definition.
|
| CVE-2016-3164 |
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might
allow remote attackers to conduct open redirect attacks by leveraging
(1) custom code or (2) a form shown on a 404 error page, related to
path manipulation.
|
| CVE-2016-3163 |
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might
make it easier for remote attackers to conduct brute-force attacks via
a large number of calls made at once to the same method.
|
| CVE-2016-3162 |
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows
remote authenticated users to bypass access restrictions and read,
delete, or substitute a link to a file uploaded to an unprocessed form
by leveraging permission to create content or comment and upload
files.
|
| CVE-2016-3144 |
Cross-site scripting (XSS) vulnerability in the Block Class module
7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users
with the "Administer block classes" permission to inject arbitrary web
script or HTML via a class name.
|
| CVE-2016-1913 |
Multiple cross-site scripting (XSS) vulnerabilities in the Redhen
module 7.x-1.x before 7.x-1.11 for Drupal allow remote authenticated
users with certain access to inject arbitrary web script or HTML via
unspecified vectors, related to (1) individual contacts, (2) notes, or
(3) engagement scores.
|
| CVE-2016-1565 |
Cross-site scripting (XSS) vulnerability in the Field Group module
7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users
with permission to configure field display settings to inject
arbitrary web script or HTML via an element attribute.
|
| CVE-2015-8761 |
The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly
check permissions, which allows remote administrators with the "Import
value sets" permission to execute arbitrary PHP code via the exported
values list in a ctools import.
|
| CVE-2015-8754 |
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote
attackers to bypass intended access restrictions and modify the mollom
blacklist via unspecified vectors.
|
| CVE-2015-8602 |
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does
not properly check permissions, which allows remote authenticated
users with certain permissions to bypass intended access restrictions
and possibly obtain sensitive information by inserting a token, which
embeds a rendered entity in the main node.
|
| CVE-2015-8601 |
The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not
properly check permissions when setting up a websocket for chat
messages, which allows remote attackers to bypass intended access
restrictions and read messages from arbitrary Chat Rooms via
unspecified vectors.
|
| CVE-2015-8233 |
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x
before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal allows remote
administrators with the "Administer themes" permission to inject
arbitrary web script or HTML via unspecified vectors related to theme
settings.
|
| CVE-2015-8232 |
The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not
properly check access to profiles in certain circumstances, which
might allow remote attackers to obtain sensitive information from the
anonymous user profile via unspecified vectors.
|
| CVE-2015-8095 |
The recycle bin feature in the Monster Menus module 7.x-1.21 before
7.x-1.24 for Drupal does not properly remove nodes from view, which
allows remote attackers to obtain sensitive information via an
unspecified URL pattern.
|
| CVE-2015-8082 |
The Login Disable module 6.x-1.x before 6.x-1.1 and 7.x-1.x before
7.x-1.2 for Drupal does not properly load the user_logout function,
which allows remote attackers to bypass the logout protection
mechanism by leveraging a contributed user authentication module, as
demonstrated by the CAS and URL Login modules.
|
| CVE-2015-8081 |
The Field as Block module 7.x-1.x before 7.x-1.4 for Drupal might
allow remote attackers to obtain sensitive field information by
reading a cached block.
|
| CVE-2015-7980 |
Cross-site scripting (XSS) vulnerability in the Compass Rose module
6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
"embedding a JavaScript library from an external source that was not
reliable."
|
| CVE-2015-7943 |
Open redirect vulnerability in the Overlay module in Drupal 7.x before
7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and
the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks via
unspecified vectors. NOTE: this vulnerability exists because of an
incomplete fix for CVE-2015-3233.
|
| CVE-2015-7881 |
The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote
authenticated users with certain permissions to bypass intended access
restrictions and "add unexpected content to a Colorbox" via
unspecified vectors, possibly related to a link in a comment.
|
| CVE-2015-7880 |
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal
allows remote attackers to obtain sensitive event registration
information by leveraging the "Register other accounts" permission and
knowledge of usernames.
|
| CVE-2015-7879 |
Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x
before 7.x-1.3 for Drupal allows remote authenticated users with
permission to create or edit a stickynote to inject arbitrary web
script or HTML via note text on the admin listing page.
|
| CVE-2015-7878 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Find module
6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0 in Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via taxonomy vocabulary and term names.
|
| CVE-2015-7877 |
Multiple SQL injection vulnerabilities in the User Dashboard module
7.x before 7.x-1.4 for Drupal allow remote attackers to execute
arbitrary SQL commands via unspecified vectors.
|
| CVE-2015-7876 |
The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver
for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly
escape certain characters, which allows remote attackers to execute
arbitrary SQL commands via vectors involving a module using the db_like
function.
|
| CVE-2015-7875 |
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal
does not verify the "edit" permission for the "content type" plugins
that are used on Panels and similar systems to place content and
functionality on a page.
|
| CVE-2015-7307 |
Cross-site scripting (XSS) vulnerability in the CMS Updater module
7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors involving the
configuration page.
|
| CVE-2015-7306 |
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not
properly check access permissions, which allows remote authenticated
users to access and change settings by leveraging the "access
administration pages" permission.
|
| CVE-2015-7305 |
The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly
restrict access to fields, which allows remote attackers to obtain
sensitive atom property information via vectors involving a "debug
context."
|
| CVE-2015-7304 |
Cross-site scripting (XSS) vulnerability in the amoCRM module 7.x-1.x
before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified HTTP POST data.
|
| CVE-2015-7234 |
The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF
Ontology and OSF Import modules are enabled, allows user-assisted
remote attackers to delete arbitrary files via unspecified vectors.
|
| CVE-2015-7233 |
Cross-site request forgery (CSRF) vulnerability in the OSF module
7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is
enabled, allows remote attackers to hijack the authentication of
administrators for requests that create new OSF datasets via
unspecified vectors.
|
| CVE-2015-7232 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the
OSF Ontology module is enabled, allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-7231 |
The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for
Drupal does not properly validate payments, which allows remote
attackers to make a failed payment appear valid via a crafted URL,
related to a "response from commweb."
|
| CVE-2015-7230 |
The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows
remote authenticated users with certain permissions to bypass node and
field validation by saving a node.
|
| CVE-2015-7229 |
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and
7.x-6.x before 7.x-6.0 for Drupal does not properly check access
permissions, which allows remote authenticated users to post tweets to
arbitrary accounts by leveraging the (1) "post to twitter" permission
or change the options for arbitrary attached accounts by leveraging
the (2) "add twitter accounts" or (3) "add authenticated twitter
accounts" permission.
|
| CVE-2015-7228 |
The RESTful module 7.x-1.x before 7.x-1.3 for Drupal does not properly
cache pages of authenticated users when using non-cookie
authentication providers, which allows remote attackers to obtain
sensitive information via unspecified vectors.
|
| CVE-2015-7227 |
The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal
does not properly check permissions to edit Fieldable Panels Panes
entities, which allows remote authenticated users to edit panes by
leveraging permissions to edit panels.
|
| CVE-2015-7226 |
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal
checks access permissions based on the router path from the view
instead of the display property, which allows remote attackers to
obtain sensitive information via vectors related to the access
handler.
|
| CVE-2015-6921 |
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab
module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators
with the "Configure Zendesk Feedback Tab" permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-6808 |
Cross-site scripting (XSS) vulnerability in the Spotlight module
7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via a
node title.
|
| CVE-2015-6807 |
Cross-site scripting (XSS) vulnerability in the Mass Contact module
6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the "administer mass contact"
permission to inject arbitrary web script or HTML via a category
label.
|
| CVE-2015-6754 |
Cross-site scripting (XSS) vulnerability in the administration
interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for
Drupal allows remote authenticated users with the "Administer Path
Breadcrumbs" permission to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-6753 |
Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit
module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via an (1) entity title, related to in-place editing, or a (2) node
title.
|
| CVE-2015-6752 |
Cross-site scripting (XSS) vulnerability in the Search API
Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search
index is configured to use the HTML filter processor, allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via unspecified vectors, which are not properly handled
in the returned suggestions.
|
| CVE-2015-6751 |
Multiple cross-site scripting (XSS) vulnerabilities in the Time
Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via a (1) note added to a time entry or an (2) activity
used to categorize time tracker entries.
|
| CVE-2015-6665 |
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal
7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via vectors involving a whitelisted HTML element, possibly related to
the "a" tag.
|
| CVE-2015-6661 |
Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to
obtain sensitive node titles by reading the menu.
|
| CVE-2015-6660 |
The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not
properly validate the form token, which allows remote attackers to
conduct CSRF attacks that upload files in a different user's account
via vectors related to "file upload value callbacks."
|
| CVE-2015-6659 |
SQL injection vulnerability in the SQL comment filtering system in the
Database API in Drupal 7.x before 7.39 allows remote attackers to
execute arbitrary SQL commands via an SQL comment.
|
| CVE-2015-6658 |
Cross-site scripting (XSS) vulnerability in the Autocomplete system in
Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to
inject arbitrary web script or HTML via a crafted URL, related to
uploading files.
|
| CVE-2015-5515 |
The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before
7.x-3.3 for Drupal, when the bulk operation for changing Roles is
enabled, allows remote authenticated users to edit user accounts and
add arbitrary roles to the accounts by leveraging access to a user
account listing view with VBO enabled.
|
| CVE-2015-5514 |
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x
before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled,
allows user-assisted remote attackers to inject arbitrary web script
or HTML via a destination field label.
|
| CVE-2015-5513 |
Cross-site scripting (XSS) vulnerability in the Shibboleth
authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before
7.x-4.2 for Drupal allows remote authenticated users with the
"Administer blocks" permission to inject arbitrary web script or HTML
via unspecified vectors related to a login link.
|
| CVE-2015-5512 |
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before
7.x-1.2 for Drupal allows remote attackers to access Views using the
"me" user argument handler by substituting "me" for a user id in a
URL.
|
| CVE-2015-5511 |
The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal
allows remote attackers to bypass the user registration by
administrator only configuration and create an account via a social
login.
|
| CVE-2015-5510 |
Open redirect vulnerability in the Content Construction Kit (CCK)
6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect
users to arbitrary web sites and conduct phishing attacks via the
destinations parameter, related to administration pages.
|
| CVE-2015-5509 |
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal,
when used with other unspecified modules, does not properly grant
access to administration pages, which allows remote administrators to
bypass intended restrictions via unspecified vectors.
|
| CVE-2015-5508 |
Cross-site request forgery (CSRF) vulnerability in the XC NCIP
Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows
remote attackers to hijack the authentication of users with the
"administer ncip providers" permission for requests that alter NCIP
providers via a crafted request.
|
| CVE-2015-5507 |
Cross-site scripting (XSS) vulnerability in the Inline Entity Form
module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated
users with permission to create or edit fields to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5506 |
The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal
does not check the status of an entity when indexing, which allows
remote attackers to obtain information about unpublished content via a
search.
|
| CVE-2015-5505 |
The HTTP Strict Transport Security (HSTS) module 6.x-1.x before
6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly
implement the "include subdomains" directive, which causes the HSTS
policy to not be applied to subdomains and allows man-in-the-middle
attackers to have unspecified impact via unknown vectors.
|
| CVE-2015-5504 |
SQL injection vulnerability in the Novalnet Payment Module Ubercart
module for Drupal allows remote attackers to execute arbitrary SQL
commands via unspecified vectors.
|
| CVE-2015-5503 |
Open redirect vulnerability in the Chamilo integration module 7.x-1.x
before 7.x-1.2 for Drupal allows remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via unspecified
parameters.
|
| CVE-2015-5502 |
The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not
properly restrict access to Storage API fields attached to entities
that are not nodes, which allows remote attackers to have unspecified
impact via unknown vectors.
|
| CVE-2015-5501 |
The Hostmaster (Aegir) module 6.x-2.x before 6.x-2.4 and 7.x-3.x
before 7.x-3.0-beta2 for Drupal allows remote attackers to execute
arbitrary PHP code via a crafted file in the directory used to write
Apache vhost files for hosted sites in a multi-site environment.
|
| CVE-2015-5500 |
Cross-site scripting (XSS) vulnerability in the Navigate module for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-5499 |
The Navigate module for Drupal does not properly check permissions,
which allows remote authenticated users to modify custom widgets and
create widget database records by leveraging the "navigate view"
permission.
|
| CVE-2015-5498 |
The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not
check the view permission for the shipments overview
(admin/shipwire/shipments), which allows remote attackers to obtain
sensitive information via a request to the page.
|
| CVE-2015-5497 |
Cross-site scripting (XSS) vulnerability in the Web Links module
6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-5496 |
The pass2pdf module for Drupal does not restrict access to generated
PDF files, which allows remote attackers to obtain user passwords via
unspecified vectors.
|
| CVE-2015-5495 |
Cross-site scripting (XSS) vulnerability in the Mobile sliding menu
module 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated
users with the "administer menu" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5494 |
Cross-site scripting (XSS) vulnerability in the Webform Matrix
Component module 7.x-4.x before 7.x-4.13 for Drupal allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5493 |
The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not
properly check permissions when a form is locked to a role, which
allows remote attackers to obtain access to certain entityforms via
unspecified vectors.
|
| CVE-2015-5492 |
Cross-site scripting (XSS) vulnerability in the Video Consultation
module for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-5491 |
The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal
allows remote authenticated users to bypass intended access
restrictions and read sensitive titles by leveraging the "administer
ddblock" permission.
|
| CVE-2015-5490 |
The _views_fetch_data method in includes/cache.inc in the Views module
7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if
the static cache is not empty, which allows remote attackers to bypass
intended filters and obtain access to hidden content via unspecified
vectors.
|
| CVE-2015-5489 |
Cross-site scripting (XSS) vulnerability in the Smart Trim module
7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
vectors involving the field settings form.
|
| CVE-2015-5488 |
Cross-site scripting (XSS) vulnerability in the MailChimp Signup
submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal
allows remote authenticated users with the "administer mailchimp"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-5487 |
Cross-site scripting (XSS) vulnerability in the Camtasia Relay module
6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows
remote authenticated users with the "view meta information" permission
to inject arbitrary web script or HTML via unspecified vectors related
to the meta access tab.
|
| CVE-2015-4398 |
Open redirect vulnerability in the Chaos tool suite (ctools) module
before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via unspecified vectors involving processing
confirmation delete pages.
|
| CVE-2015-4397 |
Cross-site request forgery (CSRF) vulnerability in the Node Template
module for Drupal allows remote attackers to hijack the authentication
of users with the "access node template" permission for requests that
delete node templates via unspecified vectors.
|
| CVE-2015-4396 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Keyword Research module 6.x-1.x before 6.x-1.2 for Drupal allow remote
attackers to hijack the authentication of users with the "kwresearch
admin site keywords" permission for requests that (1) create, (2)
delete, or (3) set priorities to keywords via unspecified vectors.
|
| CVE-2015-4395 |
The HybridAuth Social Login module 7.x-2.x before 7.x-2.10 for Drupal
stores passwords in plaintext when the "Ask user for a password when
registering" option is enabled, which allows remote authenticated
users with certain permissions to obtain sensitive information by
leveraging access to the database.
|
| CVE-2015-4394 |
The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote
attackers to bypass the field_access restriction and obtain sensitive
private field information via unspecified vectors.
|
| CVE-2015-4393 |
The resource/endpoint for uploading files in the Services module
7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users
with the "Save file information" permission to execute arbitrary code
via a crafted filename.
|
| CVE-2015-4392 |
Cross-site scripting (XSS) vulnerability in the Display Suite module
7.x-2.7 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors related to field
display settings.
|
| CVE-2015-4391 |
Cross-site request forgery (CSRF) vulnerability in the CiviCRM private
report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for
Drupal allows remote attackers to hijack the authentication of users
for requests that delete reports via unspecified vectors.
|
| CVE-2015-4390 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the User
Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x before 7.x-2.3 for
Drupal allow remote attackers to hijack the authentication of
administrators for requests that (1) continue or (2) delete an ongoing
import via unspecified vectors.
|
| CVE-2015-4389 |
The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not
properly check the create permission for content types created during
import, which allows remote authenticated users to bypass intended
restrictions by leveraging the "import og_tag_importer" permission.
|
| CVE-2015-4388 |
Cross-site scripting (XSS) vulnerability in the Current Search Links
module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the
keywords passed by the user to the list" option is disabled, allows
remote attackers to inject arbitrary web script or HTML via a crafted
search query.
|
| CVE-2015-4387 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Password Policy module 6.x-1.x before 6.x-1.11 and
7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses
the username constraint, allows remote attackers to inject arbitrary
web script or HTML via a crafted username that is imported from an
external source.
|
| CVE-2015-4386 |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified
administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal
allow remote attackers to inject arbitrary web script or HTML via
unknown vectors involving creating or editing (1) comments, (2)
taxonomy terms, or (3) nodes.
|
| CVE-2015-4385 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Imagefield Info module 7.x-1.x before 7.x-1.2 for Drupal
allows remote authenticated users with the "Administer image styles"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-4384 |
Cross-site scripting (XSS) vulnerability in the Ubercart Webform
Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.x before
7.x-3.11 for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-4383 |
Cross-site request forgery (CSRF) vulnerability in the Decisions
module for Drupal allows remote attackers to hijack the authentication
of arbitrary users for requests that remove individual voters via
unspecified vectors.
|
| CVE-2015-4382 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for
Drupal allow remote attackers to hijack the authentication of
arbitrary users for requests that (1) create, (2) delete, or (3) alter
invoices via unspecified vectors.
|
| CVE-2015-4381 |
Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x
before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote
authenticated users with the "Administer own invoices" permission to
inject arbitrary web script or HTML via unspecified vectors involving
nodes of the "Invoice" content type.
|
| CVE-2015-4380 |
Cross-site scripting (XSS) vulnerability in the Linear Case module
6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-4379 |
Cross-site request forgery (CSRF) vulnerability in the Webform
Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.x-1.x before
7.x-1.3 for Drupal allows remote attackers to hijack the
authentication of certain users for requests that delete files via
unspecified vectors.
|
| CVE-2015-4378 |
Cross-site scripting (XSS) vulnerability in the Crumbs module 7.x-2.x
before 7.x-2.3 for Drupal allows remote authenticated users with the
"Administer Crumbs" permission to inject arbitrary web script or HTML
via a custom breadcrumb separator.
|
| CVE-2015-4377 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows
remote authenticated users with the "create petition" permission to
inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2015-4376 |
Cross-site scripting (XSS) vulnerability in the Profile2 Privacy
module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated
users with the "Administer Profile2 Privacy Levels" permission to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4375 |
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal
allows remote attackers to obtain sensitive node titles via (1) an
autocomplete search on custom entities without an access query tag or
(2) leveraging knowledge of the ID of an entity.
|
| CVE-2015-4374 |
Cross-site scripting (XSS) vulnerability in the Webform module before
6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via a component name in the
recipient (To) address of an email.
|
| CVE-2015-4373 |
Cross-site scripting (XSS) vulnerability in the OG tabs module before
7.x-1.1 for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via vectors related
to nodes posted in an Organic Groups group.
|
| CVE-2015-4372 |
Cross-site scripting (XSS) vulnerability in the Image Title module
before 7.x-1.1 for Drupal allows remote authenticated users with
certain permissions to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-4371 |
Open redirect vulnerability in the Perfecto module before 7.x-1.2 for
Drupal allows remote attackers to redirect users to arbitrary web
sites and conduct phishing attacks via a URL in an unspecified
parameter.
|
| CVE-2015-4370 |
Cross-site scripting (XSS) vulnerability in the Site Documentation
module before 6.x-1.5 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
vectors related to taxonomy terms.
|
| CVE-2015-4369 |
Cross-site scripting (XSS) vulnerability in the Trick Question module
before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal allows remote
authenticated users with the "Administer Trick Question" permission to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4368 |
The Commerce Ogone module 7.x-1.x before 7.x-1.5 for Drupal allows
remote attackers to complete the checkout for an order without paying
via unspecified vectors.
|
| CVE-2015-4367 |
Cross-site scripting (XSS) vulnerability in the Simple Subscription
module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the "administer blocks" permission to
inject arbitrary web script or HTML via vectors related to block
content.
|
| CVE-2015-4366 |
Cross-site scripting (XSS) vulnerability in the Mover module 6.x-1.0
for Drupal allows remote authenticated users with certain permissions
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4365 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Accordion
module for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via vectors related
to taxonomy terms.
|
| CVE-2015-4364 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
includes/campaignmonitor_lists.admin.inc in the Campaign Monitor
module 7.x-1.0 for Drupal allow remote attackers to hijack the
authentication of users for requests that (1) enable list
subscriptions via a request to
admin/config/services/campaignmonitor/lists/%/enable or (2) disable
list subscriptions via a request to
admin/config/services/campaignmonitor/lists/%/disable.
|
| CVE-2015-4363 |
Open redirect vulnerability in the finder_form_goto function in the
Finder module for Drupal allows remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via unspecified
vectors.
|
| CVE-2015-4362 |
Cross-site request forgery (CSRF) vulnerability in
tracking_code.admin.inc in the Tracking Code module 7.x-1.x before
7.x-1.6 for Drupal allows remote attackers to hijack the
authentication of administrators for requests that disable tracking
codes via unspecified vectors.
|
| CVE-2015-4361 |
Cross-site request forgery (CSRF) vulnerability in the Registration
codes module before 6.x-1.6 for Drupal allows remote attackers to
hijack the authentication of administrators for requests that delete
registration codes via unspecified vectors.
|
| CVE-2015-4360 |
Cross-site request forgery (CSRF) vulnerability in the Registration
codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8, and 7.x-1.x
before 7.x-1.2 for Drupal allows remote attackers to hijack the
authentication of administrators for requests that delete role-rules
via unspecified vectors.
|
| CVE-2015-4359 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Registration codes module before 6.x-1.6, 6.x-2.x before 6.x-2.8, and
7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users
with permission to create or edit taxonomy terms or nodes to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4358 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Ubercart Discount Coupons module 6.x-1.x before 6.x-1.8
for Drupal allows remote authenticated users with certain permissions
to inject arbitrary web script or HTML via vectors related to taxonomy
terms.
|
| CVE-2015-4357 |
Cross-site scripting (XSS) vulnerability in the Webform module before
6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via a node title, which is used as
the default title of a webform block.
|
| CVE-2015-4356 |
Cross-site scripting (XSS) vulnerability in the view-based webform
results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via a webform.
|
| CVE-2015-4355 |
Cross-site request forgery (CSRF) vulnerability in the Watchdog
Aggregator module for Drupal allows remote attackers to hijack the
authentication of administrators for requests that enable or disable
monitoring sites via unspecified vectors.
|
| CVE-2015-4354 |
Cross-site scripting (XSS) vulnerability in the Ubercart Webform
Integration module before 6.x-1.8 and 7.x before 7.x-2.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-4353 |
Cross-site request forgery (CSRF) vulnerability in the Custom Sitemap
module for Drupal allows remote attackers to hijack the authentication
of administrators for requests that delete sitemaps via unspecified
vectors.
|
| CVE-2015-4352 |
Cross-site request forgery (CSRF) vulnerability in the Spider Video
Player module for Drupal allows remote attackers to hijack the
authentication of administrators for requests that delete videos via
unspecified vectors.
|
| CVE-2015-4351 |
The Spider Video Player module for Drupal allows remote authenticated
users with the "access Spider Video Player administration" permission
to delete arbitrary files via a crafted URL.
|
| CVE-2015-4350 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Spider Catalog module for Drupal allow remote attackers to hijack the
authentication of administrators for requests that delete (1)
products, (2) ratings, or (3) categories via unspecified vectors.
|
| CVE-2015-4349 |
Cross-site request forgery (CSRF) vulnerability in the Spider Contacts
module for Drupal allows remote attackers to hijack the authentication
of administrators for requests that delete contact categories via
unspecified vectors.
|
| CVE-2015-4348 |
SQL injection vulnerability in the Spider Contacts module for Drupal
allows remote authenticated users with the "access Spider Contacts
category administration" permission to execute arbitrary SQL commands
via unspecified vectors.
|
| CVE-2015-4347 |
Cross-site scripting (XSS) vulnerability in the inLinks Integration
module for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified path arguments.
|
| CVE-2015-4346 |
Cross-site scripting (XSS) vulnerability in the SMS Framework module
6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule
is enabled, allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors related to message previews.
|
| CVE-2015-4345 |
The RESTWS Basic Auth submodule in the RESTful Web Services module
7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches
pages for authenticated requests, which allows remote attackers to
obtain sensitive information via unspecified vectors.
|
| CVE-2015-4344 |
The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for
Drupal allows remote attackers to bypass intended resource
restrictions via vectors related to page caching.
|
| CVE-2015-3404 |
The Certify module before 6.x-2.3 for Drupal does not properly perform
node access checks, which allows remote authenticated users to bypass
intended access restrictions and obtain sensitive PDF certificate
information via vectors related to "showing (and creating) the PDF
certificates."
|
| CVE-2015-3393 |
Open redirect vulnerability in the Commerce WeDeal module before
7.x-1.3 for Drupal allows remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via an unspecified
parameter.
|
| CVE-2015-3392 |
Cross-site scripting (XSS) vulnerability in the Ajax Timeline module
before 7.x-1.1 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3391 |
The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote
attackers to bypass intended access restrictions and obtaining
sensitive node titles by reading a 403 Not Found page.
|
| CVE-2015-3390 |
Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher
module for Drupal allows remote authenticated users with the "access
administration pages" permission to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2015-3389 |
Cross-site scripting (XSS) vulnerability in the Download counts report
page in the Public Download Count module (pubdlcnt) 7.x-1.x-dev and
earlier for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-3388 |
Cross-site request forgery (CSRF) vulnerability in the Commerce
Balanced Payments module for Drupal allows remote attackers to hijack
the authentication of arbitrary users for requests that delete the
user's configured bank accounts via unspecified vectors.
|
| CVE-2015-3387 |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy
Tools module before 7.x-1.4 for Drupal allow remote authenticated
users to inject arbitrary web script or HTML via a (1) node or (2)
taxonomy term title.
|
| CVE-2015-3386 |
Cross-site scripting (XSS) vulnerability in the Node Access Product
module for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3385 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Path module
before 7.x-1.2 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via the "Link to path" field formatter.
|
| CVE-2015-3384 |
Cross-site scripting (XSS) vulnerability in the Bank Account Listing
Page in the Commerce Balanced Payments module for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-3383 |
Open redirect vulnerability in the Node basket module for Drupal
allows remote attackers to redirect users to arbitrary web sites and
conduct phishing attacks via unspecified vectors.
|
| CVE-2015-3382 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Node
basket module for Drupal allow remote attackers to hijack the
authentication of arbitrary users for requests that (1) add or (2)
remove nodes from a basket via unspecified vectors.
|
| CVE-2015-3381 |
Cross-site scripting (XSS) vulnerability in the Node basket module for
Drupal allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2015-3380 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Feature Set module for Drupal allow remote attackers to hijack the
authentication of administrators for requests that (1) enable or (2)
disable a module via unspecified vectors.
|
| CVE-2015-3379 |
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x
before 7.x-3.10 for Drupal does not properly restrict access to the
default views configurations, which allows remote authenticated users
to obtain sensitive information via unspecified vectors.
|
| CVE-2015-3378 |
Open redirect vulnerability in the Views module before 6.x-2.18,
6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when
the Views UI submodule is enabled, allows remote authenticated users
to redirect users to arbitrary web sites and conduct phishing attacks
via vectors related to the break lock page for edited views.
|
| CVE-2015-3376 |
Cross-site scripting (XSS) vulnerability in the Quizzler module before
7-x.1.16 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3375 |
Cross-site request forgery (CSRF) vulnerability in the Shibboleth
Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for
Drupal allows remote attackers to hijack the authentication of
administrators for requests that delete user role matching rules via
unspecified vectors.
|
| CVE-2015-3374 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Corner module for Drupal allow remote attackers to hijack the
authentication of administrators for requests that (1) enable or (2)
disable corners via unspecified vectors.
|
| CVE-2015-3373 |
The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and
AWS access key to generate the access token, which makes it easier for
remote attackers to guess the token value and create backups via a
crafted URL.
|
| CVE-2015-3372 |
Cross-site scripting (XSS) vulnerability in the Node Invite module
before 6.x-2.5 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3371 |
Open redirect vulnerability in the Node Invite module before 6.x-2.5
for Drupal allows remote attackers to redirect users to arbitrary web
sites and conduct phishing attacks via the destination parameter.
|
| CVE-2015-3370 |
Cross-site request forgery (CSRF) vulnerability in the Node Invite
module before 6.x-2.5 for Drupal allows remote attackers to hijack the
authentication of users with the "node_invite_can_manage_invite"
permission for requests that re-enable node invitations via
unspecified vectors.
|
| CVE-2015-3369 |
Cross-site scripting (XSS) vulnerability in the Taxonews module before
6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote
authenticated users with the "administer taxonomy" permission to
inject arbitrary web script or HTML via a term name in a block.
|
| CVE-2015-3368 |
Cross-site scripting (XSS) vulnerability in the administration user
interface in the Classified Ads module before 6.x-3.1 and 7.x-3.x
before 7.x-3.1 for Drupal allows remote authenticated users with the
"administer taxonomy" permission to inject arbitrary web script or
HTML via a category name.
|
| CVE-2015-3367 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Patterns module before 7.x-2.2 for Drupal allow remote attackers to
hijack the authentication of administrators for requests that (1)
restore, (2) publish, or (3) unpublish a pattern via unspecified
vectors.
|
| CVE-2015-3366 |
Cross-site request forgery (CSRF) vulnerability in the Alfresco module
before 6.x-1.3 for Drupal allows remote attackers to hijack the
authentication of arbitrary users for requests that delete an alfresco
node via unspecified vectors.
|
| CVE-2015-3365 |
Cross-site scripting (XSS) vulnerability in the nodeauthor module for
Drupal allows remote authenticated users to inject arbitrary web
script or HTML via a Profile2 field in a provided block.
|
| CVE-2015-3364 |
Cross-site scripting (XSS) vulnerability in the Content Analysis
module before 6.x-1.7 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, which are not
properly handled in a log message.
|
| CVE-2015-3363 |
Cross-site request forgery (CSRF) vulnerability in the Contact Form
Fields module before 6.x-2.3 for Drupal allows remote attackers to
hijack the authentication of administrators for requests that delete
fields via unspecified vectors.
|
| CVE-2015-3362 |
Cross-site scripting (XSS) vulnerability in the Video module before
7.x-2.11 for Drupal, when using the video WYSIWYG plugin, allows
remote authenticated users to inject arbitrary web script or HTML via
a node title.
|
| CVE-2015-3361 |
Cross-site scripting (XSS) vulnerability in the Linkit module before
7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when the node search
plugin is enabled, allows remote authenticated users to inject
arbitrary web script or HTML via a node title.
|
| CVE-2015-3360 |
Cross-site scripting (XSS) vulnerability in the Term Merge module
before 7.x-1.2 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-3359 |
Multiple cross-site scripting (XSS) vulnerabilities in the Room
Reservations module before 7.x-1.1 for Drupal allow remote
authenticated users with the "Administer the room reservations system"
permission to inject arbitrary web script or HTML via the (1) node
title of a "Room Reservations Category" or (2) body of a "Room
Reservations Room" node.
|
| CVE-2015-3358 |
Multiple open redirect vulnerabilities in the Tadaa! module before
7.x-1.4 for Drupal allow remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via a URL in a
destination parameter, related to callbacks that (1) enable and
disable modules or (2) change variables.
|
| CVE-2015-3357 |
Cross-site scripting (XSS) vulnerability in the Wishlist module before
6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote
authenticated users with the "access wishlists" permission to inject
arbitrary web script or HTML via unspecified vectors, which are not
properly handled in a log message.
|
| CVE-2015-3356 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Tadaa! module before 7.x-1.4 for Drupal allow remote attackers to
hijack the authentication of arbitrary users for requests that (1)
enable or (2) disable modules or (3) change variables via unspecified
vectors.
|
| CVE-2015-3355 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Batch Jobs module before 7.x-1.2 for Drupal allow remote attackers to
hijack the authentication of certain users for requests that (1)
delete a batch job record or (2) execute a task via unspecified
vectors.
|
| CVE-2015-3354 |
Cross-site request forgery (CSRF) vulnerability in the Wishlist module
before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote
attackers to hijack the authentication of arbitrary users for requests
that delete wishlist purchase intentions via unspecified vectors.
|
| CVE-2015-3353 |
Cross-site scripting (XSS) vulnerability in the Field Display Label
module before 7.x-1.3 for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via the alternate field label in
content types settings.
|
| CVE-2015-3352 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Jammer module before 6.x-1.8 and 7.x-1.x before 7.x-1.4 for Drupal
allow remote attackers to hijack the authentication of administrators
for requests that delete a setting for (1) hidden form elements or (2)
status messages via unspecified vectors, related to "report
administration."
|
| CVE-2015-3351 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Log
Watcher module before 6.x-1.2 for Drupal allow remote attackers to
hijack the authentication of administrators for requests that (1)
enable, (2) disable, or (3) delete a report via unspecified vectors.
|
| CVE-2015-3350 |
Cross-site request forgery (CSRF) vulnerability in the Todo Filter
module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote attackers to hijack the authentication of arbitrary users for
requests that toggle a task via unspecified vectors.
|
| CVE-2015-3349 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Htaccess module before 7.x-2.3 for Drupal allow remote attackers to
hijack the authentication of administrators for requests that (1)
deploy or (2) delete an .htaccess file via unspecified vectors.
|
| CVE-2015-3348 |
Cross-site scripting (XSS) vulnerability in the Cloudwords for
Multilingual Drupal module before 7.x-2.3 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a node
title.
|
| CVE-2015-3347 |
Cross-site request forgery (CSRF) vulnerability in the Cloudwords for
Multilingual Drupal module before 7.x-2.3 for Drupal allows remote
attackers to hijack the authentication of unspecified victims via an
unknown menu callback.
|
| CVE-2015-3346 |
SQL injection vulnerability in the WikiWiki module before 6.x-1.2 for
Drupal allows remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2015-3345 |
SQL injection vulnerability in the PHPlist Integration Module before
6.x-1.7 for Drupal allows remote administrators to execute arbitrary
SQL commands via unspecified vectors, related to the "phpList
database."
|
| CVE-2015-3344 |
Cross-site scripting (XSS) vulnerability in the Course module 6.x-1.x
before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a node
title.
|
| CVE-2015-3343 |
Cross-site request forgery (CSRF) vulnerability in the OPAC module
before 7.x-2.3 for Drupal allows remote attackers to hijack the
authentication of unspecified victims for requests that remove a
mapping via unknown vectors.
|
| CVE-2015-3342 |
Open redirect vulnerability in the Ubercart Currency Conversion module
before 6.x-1.2 for Drupal allows remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via a URL in the
destination query parameter.
|
| CVE-2015-3234 |
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows
remote attackers to log into other users' accounts by leveraging an
OpenID identity from certain providers, as demonstrated by the
Verisign, LiveJournal, and StackExchange providers.
|
| CVE-2015-3233 |
Open redirect vulnerability in the Overlay module in Drupal 7.x before
7.38 allows remote attackers to redirect users to arbitrary web sites
and conduct phishing attacks via unspecified vectors.
|
| CVE-2015-3232 |
Open redirect vulnerability in the Field UI module in Drupal 7.x
before 7.38 allows remote attackers to redirect users to arbitrary web
sites and conduct phishing attacks via a URL in the destinations
parameter.
|
| CVE-2015-3231 |
The Render cache system in Drupal 7.x before 7.38, when used to cache
content by user role, allows remote authenticated users to obtain
private content viewed by user 1 by reading the cache.
|
| CVE-2015-2750 |
Open redirect vulnerability in URL-related API functions in Drupal 6.x
before 6.35 and 7.x before 7.35 allows remote attackers to redirect
users to arbitrary web sites and conduct phishing attacks via vectors
involving the "//" initial sequence.
|
| CVE-2015-2749 |
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before
7.35 allows remote attackers to redirect users to arbitrary web sites
and conduct phishing attacks via a URL in the destination parameter.
|
| CVE-2015-2559 |
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated
users to reset the password of other accounts by leveraging an account
with the same password hash as another account and a crafted password
reset URL.
|
| CVE-2015-2215 |
Open redirect vulnerability in the Services single sign-on server
helper (services_sso_server_helper) module for Drupal allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via unspecified parameters.
|
| CVE-2015-2197 |
Cross-site scripting (XSS) vulnerability in the Entity API module
before 7.x-1.6 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via a field label in the Token API.
|
| CVE-2015-2101 |
Cross-site scripting (XSS) vulnerability in the Navigate bar in the
Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2015-2088 |
Cross-site scripting (XSS) vulnerability in unspecified administration
pages in the Term Queue module before 6.x-1.1 for Drupal allows remote
attackers to inject arbitrary web script or HTML via unknown vectors.
|
| CVE-2015-2087 |
Unrestricted file upload vulnerability in the Avatar Uploader module
before 6.x-1.3 for Drupal allows remote authenticated users to execute
arbitrary PHP code by uploading a file with a PHP extension, then
accessing it via unspecified vectors.
|
| CVE-2015-2086 |
Cross-site scripting (XSS) vulnerability in the live preview in the
Panopoly Magic module before 7.x-1.17 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a pane
title.
|
| CVE-2015-1621 |
Cross-site scripting (XSS) vulnerability in the Webform prepopulate
block module before 7.x-3.1 for Drupal allows remote authenticated
users to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2015-1568 |
Cross-site request forgery (CSRF) vulnerability in the GD Infinite
Scroll module before 7.x-1.4 for Drupal allows remote attackers to
hijack the authentication of users with the "edit gd infinite scroll
settings" permission for requests that delete settings via unspecified
vectors.
|
| CVE-2015-1567 |
Cross-site scripting (XSS) vulnerability in the admin page in the GD
Infinite Scroll module before 7.x-1.4 for Drupal allows remote
authenticated users with the "edit gd infinite scroll settings"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2015-1051 |
Open redirect vulnerability in the Context UI module in the Context
module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to
redirect users to arbitrary web sites and conduct phishing attacks via
a URL in the destination parameter.
|
| CVE-2014-9740 |
Cross-site scripting (XSS) vulnerability in the Rules Link module
7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users
with the "administer rules links" permission to inject arbitrary web
script or HTML via unspecified vectors, which are not properly handled
in the (1) question and (2) description strings in a confirmation form
for a triggering Rules link.
|
| CVE-2014-9739 |
Cross-site scripting (XSS) vulnerability in the Node Field module
7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
unspecified vectors involving internal fields.
|
| CVE-2014-9738 |
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament
module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via an (1) account username, a (2) node title, or a (3) team entity
title.
|
| CVE-2014-9737 |
Open redirect vulnerability in the Language Switcher Dropdown module
7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect
users to arbitrary web sites and conduct phishing attacks via a URL in
a block.
|
| CVE-2014-9505 |
Cross-site scripting (XSS) vulnerability in the School Administration
module 7.x-1.x before 7.x-1.8 for Drupal allows remote authenticated
users with permission to create or edit a class node to inject
arbitrary web script or HTML via a node title.
|
| CVE-2014-9501 |
Cross-site scripting (XSS) vulnerability in the Poll Chart Block
module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated
users to inject arbitrary web script or HTML via a poll node title.
|
| CVE-2014-9500 |
Cross-site scripting (XSS) vulnerability in the Moip module 7.x-1.x
before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors to the notification page
callback.
|
| CVE-2014-9499 |
Cross-site scripting (XSS) vulnerability in the Godwin's Law module
before 7.x-1.1 for Drupal, when using the dblog module, allows remote
authenticated users to inject arbitrary web script or HTML via a
Watchdog message.
|
| CVE-2014-9498 |
Cross-site scripting (XSS) vulnerability in the Webform Invitation
module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.4 for Drupal
allows remote authenticated users with the Webform: Create new
content, Webform: Edit own content, or Webform: Edit any content
permission to inject arbitrary web script or HTML via a node title.
|
| CVE-2014-9364 |
Cross-site scripting (XSS) vulnerability in the Unified Login form in
the LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2014-9363 |
Open redirect vulnerability in the path-based meta tag editing form in
the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows
remote authenticated users to redirect users to arbitrary web sites
and conduct phishing attacks via the destination parameter.
|
| CVE-2014-9362 |
Cross-site scripting (XSS) vulnerability in the path-based meta tag
editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for
Drupal allows remote authenticated users with the "Edit path based
meta tags" permission to inject arbitrary web script or HTML via
vectors related to deleting a Path-based Metatag.
|
| CVE-2014-9361 |
The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not
properly unset the authorized user role for certain users, which
allows remote attackers with the pre-authorized role to gain
privileges and possibly obtain sensitive information by accessing a
Page Not Found (404) page.
|
| CVE-2014-9346 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via vectors related to the (1) taxonomy
term title for instances with Save term lineage enabled or (2) entity
type fields.
|
| CVE-2014-9156 |
The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not
properly check permissions to view files, which allows remote
authenticated users with permission to create or edit content to read
private files by attaching an uploaded file.
|
| CVE-2014-9155 |
Directory traversal vulnerability in the Avatar Uploader module
6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal
allows remote authenticated users to read arbitrary files via a ..
(dot dot) in the path of a cropped picture in the uploader panel.
|
| CVE-2014-9154 |
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly
restrict access to (1) new or (2) modified nodes or (3) their fields,
which allows remote authenticated users to obtain node titles,
teasers, and fields by reading a notification email.
|
| CVE-2014-9153 |
Cross-site scripting (XSS) vulnerability in the Services module
7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users
to inject arbitrary web script or HTML via the callback parameter in a
JSONP response.
|
| CVE-2014-9152 |
The _user_resource_create function in the Services module 7.x-3.x
before 7.x-3.10 for Drupal uses a password of 1 when creating new user
accounts, which makes it easier for remote attackers to guess the
password via a brute force attack.
|
| CVE-2014-9151 |
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not
properly limit the rate of authentication attempts, which makes it
easier for remote attackers to obtain access via a brute-force attack
on the administrative password.
|
| CVE-2014-9026 |
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not
properly protect the per-user order history view, which allows remote
authenticated users with the "view own orders" permission to obtain
sensitive information via unspecified vectors.
|
| CVE-2014-9025 |
The default checkout completion rule in the commerce_order module in
the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the
email address as the username for new accounts created at checkout,
which allows remote attackers to obtain sensitive information via
unspecified vectors.
|
| CVE-2014-9024 |
The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows
remote attackers to bypass the password protection via a crafted path.
|
| CVE-2014-9023 |
The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly
restrict access to the Twilio administration pages, which allows
remote authenticated users to read and modify authentication tokens by
leveraging the "access administration pages" Drupal permission.
|
| CVE-2014-9022 |
The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x
before 7.x-1.8 for Drupal allows remote attackers to bypass the
"disabled" restriction and modify read-only components via a crafted
form.
|
| CVE-2014-9016 |
The password hashing API in Drupal 7.x before 7.34 and the Secure
Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal
allows remote attackers to cause a denial of service (CPU and memory
consumption) via a crafted request.
|
| CVE-2014-9015 |
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to
hijack sessions via a crafted request, as demonstrated by a crafted
request to a server that supports both HTTP and HTTPS sessions.
|
| CVE-2014-8765 |
Multiple cross-site scripting (XSS) vulnerabilities in the Project
Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for
Drupal allow (1) remote attackers to inject arbitrary web script or
HTML via a crafted patch, which triggers a PIFR client to test the
patch and return the results to the PIFR_Server test results page or
(2) remote authenticated users with the "manage PIFR environments"
permission to inject arbitrary web script or HTML via vectors
involving a PIFR_Server administrative page.
|
| CVE-2014-8748 |
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for
Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows
remote authenticated users with the "administer dfp" permission to
inject arbitrary web script or HTML via a slot name.
|
| CVE-2014-8747 |
Cross-site scripting (XSS) vulnerability in the Drupal Commons module
7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject
arbitrary web script or HTML via vectors related to content creation
and activity stream messages.
|
| CVE-2014-8746 |
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2
through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated
users with the "administer themes" permission to inject arbitrary web
script or HTML via vectors related to theme settings.
|
| CVE-2014-8745 |
Cross-site scripting (XSS) vulnerability in the Custom Search module
6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows
remote authenticated users with the "administer taxonomy" permission
to inject arbitrary web script or HTML via a taxonomy vocabulary
label.
|
| CVE-2014-8744 |
Cross-site scripting (XSS) vulnerability in the Nivo Slider module
7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users
with the "administer nivo slider" permission to inject arbitrary web
script or HTML via an image title.
|
| CVE-2014-8743 |
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro
module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via a (1) Role or (2) Organic Group name.
|
| CVE-2014-8736 |
The Open Atrium Core module for Drupal before 7.x-2.22 allows remote
attackers to bypass access restrictions and read file attachments that
have been removed from a node by leveraging a previous revision of the
node.
|
| CVE-2014-8735 |
The Bad Behavior module 6.x-2.x before 6.x-2.2216 and 7.x-2.x before
7.x-2.2216 for Drupal logs usernames and passwords, which allows
remote authenticated users with the "administer bad behavior"
permission to obtain sensitive information by reading a log file.
|
| CVE-2014-8734 |
The Organic Groups Menu (aka OG Menu) module before 7.x-2.2 for Drupal
allows remote authenticated users with the "access administration
pages" permission to change module settings via unspecified vectors.
|
| CVE-2014-8379 |
Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA
module before 7.x-1.5 for Drupal allow remote authenticated users with
certain permissions to inject arbitrary web script or HTML via vectors
related to field titles to the (1) Webform or (2) User sub-modules.
|
| CVE-2014-8376 |
Cross-site scripting (XSS) vulnerability in the context administration
sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows
remote authenticated users with the "Administer contexts" Context UI
module permission to inject arbitrary web script or HTML via vectors
related to context settings.
|
| CVE-2014-8320 |
Cross-site scripting (XSS) vulnerability in the Custom Search module
6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via the "Label text" field to the results
configuration page.
|
| CVE-2014-8319 |
Cross-site scripting (XSS) vulnerability in the
easy_social_admin_summary function in the Easy Social module 7.x-2.x
before 7.x-2.11 for Drupal allows remote authenticated users with
certain permissions to inject arbitrary web script or HTML via a block
title.
|
| CVE-2014-8318 |
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x
before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before
7.x-4.0-beta2 for Drupal allows remote authenticated users with
certain permissions to inject arbitrary web script or HTML via a field
label title, when two fields have the same form_key.
|
| CVE-2014-8317 |
Cross-site scripting (XSS) vulnerability in the Webform Validation
module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via a component name text.
|
| CVE-2014-8296 |
Cross-site scripting (XSS) vulnerability in the Modal Frame API module
6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-8079 |
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x
before 7.x-1.3 for Drupal allows remote authenticated users with the
"administer themes" permission to inject arbitrary web script or HTML
via vectors related to header background setting.
|
| CVE-2014-8078 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x
before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via vectors related to nodes.
|
| CVE-2014-8077 |
Cross-site scripting (XSS) vulnerability in the NewsFlash theme
6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows
remote authenticated users with the "administer themes" permission to
inject arbitrary web script or HTML via vectors related to font family
CSS property.
|
| CVE-2014-8076 |
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x
before 7.x-2.04 for Drupal allows remote authenticated users with the
"administer themes" permission to inject arbitrary web script or HTML
via vectors related to custom copyright information.
|
| CVE-2014-8075 |
Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x
and 7.x-3.x for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via a node title.
|
| CVE-2014-7980 |
Multiple cross-site scripting (XSS) vulnerabilities in template.php in
Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal
allow remote authenticated users with the "administer themes"
permission to inject arbitrary web script or HTML via the
skip_link_text setting and unspecified other theme settings.
|
| CVE-2014-7979 |
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme
7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users
with the "administer themes" permission to inject arbitrary web script
or HTML via vectors related to theme settings.
|
| CVE-2014-7978 |
Cross-site scripting (XSS) vulnerability in the BlueMasters theme
7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users
with the "administer themes" permission to inject arbitrary web script
or HTML via vectors related to theme settings.
|
| CVE-2014-7870 |
Cross-site scripting (XSS) vulnerability in the Custom Search module
6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows
remote authenticated users with the "administer custom search"
permission to inject arbitrary web script or HTML via the "Label text"
field to admin/config/search/custom_search/results.
|
| CVE-2014-7869 |
Cross-site scripting (XSS) vulnerability in the configuration UI in
the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal
allows remote authenticated users with the "administer contexts"
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2014-5456 |
Cross-site scripting (XSS) vulnerability in the Social Stats module
before 7.x-1.5 for Drupal allows remote authenticated users with the
"[Content Type]: Create new content" permission to inject arbitrary
web script or HTML via vectors related to the configuration.
|
| CVE-2014-5268 |
The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote
attackers to block or unblock an account via a crafted user status
link.
|
| CVE-2014-5267 |
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31
allows remote attackers to have unspecified impact via a crafted
DOCTYPE declaration in an XRDS document.
|
| CVE-2014-5266 |
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2
and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the
number of elements in an XML document, which allows remote attackers
to cause a denial of service (CPU consumption) via a large document, a
different vulnerability than CVE-2014-5265.
|
| CVE-2014-5265 |
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2
and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity
declarations without considering recursion during entity expansion,
which allows remote attackers to cause a denial of service (memory and
CPU consumption) via a crafted XML document containing a large number
of nested entity references, a similar issue to CVE-2003-1564.
|
| CVE-2014-5250 |
Unspecified vulnerability in the AJAX autocompletion callback in the
Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before
7.x-1.5 for Drupal allows remote attackers to access data via
unspecified vectors.
|
| CVE-2014-5249 |
SQL injection vulnerability in the "Biblio self autocomplete"
submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and
7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute
arbitrary SQL commands via unspecified vectors.
|
| CVE-2014-5179 |
The freelinking module for Drupal, as used in the Freelinking for Case
Tracker module, does not properly check access permissions for (1)
nodes or (2) users, which allows remote attackers to obtain sensitive
information via a crafted link.
|
| CVE-2014-5169 |
Cross-site scripting (XSS) vulnerability in the Date module before
7.x-2.8 for Drupal allows remote authenticated users with the
permission to create a date field to inject arbitrary web script or
HTML via the date field title.
|
| CVE-2014-5022 |
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal
7.x before 7.29 allows remote attackers to inject arbitrary web script
or HTML via vectors involving forms with an Ajax-enabled textfield and
a file field.
|
| CVE-2014-5021 |
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x
before 6.32 and possibly 7.x before 7.29 allows remote authenticated
users with the "administer taxonomy" permission to inject arbitrary
web script or HTML via an option group label.
|
| CVE-2014-5020 |
The File module in Drupal 7.x before 7.29 does not properly check
permissions to view files, which allows remote authenticated users
with certain permissions to bypass intended restrictions and read
files by attaching the file to content with a file field.
|
| CVE-2014-5019 |
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29
allows remote attackers to cause a denial of service via a crafted
HTTP Host header, related to determining which configuration file to
use.
|
| CVE-2014-4506 |
Cross-site scripting (XSS) vulnerability in the Custom Meta module
6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows
remote authenticated users with the "administer custom meta settings"
permission to inject arbitrary web script or HTML via the (1)
attribute or (2) content value for a meta tag.
|
| CVE-2014-4505 |
Cross-site scripting (XSS) vulnerability in the Easy Breadcrumb module
7.x-2.x before 7.x-2.10 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2014-4303 |
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme
7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users
with the Administer themes permission to inject arbitrary web script
or HTML via vectors related to the (1) Twitter and (2) Facebook
username settings.
|
| CVE-2014-3933 |
Cross-site scripting (XSS) vulnerability in the address components
field formatter in the AddressField Tokens module 7.x-1.x before
7.x-1.4 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via an address field.
|
| CVE-2014-3704 |
The expandArguments function in the database abstraction API in Drupal
core 7.x before 7.32 does not properly construct prepared statements,
which allows remote attackers to conduct SQL injection attacks via an
array containing crafted keys.
|
| CVE-2014-3453 |
Eval injection vulnerability in the flag_import_form_validate function
in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and
earlier for Drupal allows remote authenticated administrators to
execute arbitrary PHP code via the "Flag import code" text area to
admin/structure/flags/import. NOTE: this issue could also be exploited
by other attackers if the administrator ignores a security warning on
the permissions assignment page.
|
| CVE-2014-2983 |
Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate
the cached data of different anonymous users, which allows remote
anonymous users to obtain sensitive interim form input information in
opportunistic situations via unspecified vectors.
|
| CVE-2014-2715 |
Multiple cross-site scripting (XSS) vulnerabilities in
vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugins
for Drupal 7.x allow remote attackers to inject arbitrary web script
or HTML via the (1) module or (2) message parameter to index.php.
|
| CVE-2014-1611 |
Cross-site scripting (XSS) vulnerability in the Anonymous Posting
module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to
inject arbitrary web script or HTML via the contact name field.
|
| CVE-2014-1607 |
** DISPUTED ** Cross-site scripting (XSS) vulnerability in the
EventCalendar module for Drupal 7.14 allows remote attackers to inject
arbitrary web script or HTML via the year parameter to eventcalander/.
NOTE: this issue has been disputed by the Drupal Security Team; it may
be site-specific. If so, then this CVE will be REJECTed in the
future.
|
| CVE-2014-1476 |
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an
earlier version of Drupal, does not properly restrict access to
unpublished content, which allows remote authenticated users to obtain
sensitive information via a listing page.
|
| CVE-2014-1475 |
The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows
remote OpenID users to authenticate as other users via unspecified
vectors.
|
| CVE-2013-7407 |
Cross-site request forgery (CSRF) vulnerability in the MRBS module for
Drupal allows remote attackers to hijack the authentication of
unspecified victims via unknown vectors.
|
| CVE-2013-7406 |
SQL injection vulnerability in the MRBS module for Drupal allows
remote attackers to execute arbitrary SQL commands via unspecified
vectors.
|
| CVE-2013-7391 |
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using
the (a) Views field or (b) area plugins, allows remote attackers to
read restricted entities via the (1) field, (2) header, or (3) footer
of a View. NOTE: this identifier was SPLIT from CVE-2013-4273 per ADT5
due to different researcher organizations.
|
| CVE-2013-7302 |
Session fixation vulnerability in the Ubercart module 6.x-2.x before
6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new
customers after checkout" option is enabled, allows remote attackers
to hijack web sessions by leveraging knowledge of the original session
ID.
|
| CVE-2013-7068 |
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal
allows remote authenticated users to bypass group restrictions on
nodes with all groups set to optional input via an empty group field.
|
| CVE-2013-7067 |
The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not
properly override pages that have an access callback set to false,
which allows remote attackers to bypass intended access restrictions
via a request.
|
| CVE-2013-7066 |
The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal
allows remote attackers to read private nodes titles by leveraging
edit permissions to a node that references a private node.
|
| CVE-2013-7065 |
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal
allows remote attackers to bypass access restrictions and post to
arbitrary groups via a group audience field, as demonstrated by the
og_group_ref field.
|
| CVE-2013-7064 |
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance
module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated
administrators with the "Administer EU Cookie Compliance popup"
permission to inject arbitrary web script or HTML via unspecified
configuration values.
|
| CVE-2013-7063 |
The Invitation module 7.x-2.x for Drupal does not properly check
permissions, which allows remote attackers to obtain sensitive
information via unspecified default views.
|
| CVE-2013-6389 |
Open redirect vulnerability in the Overlay module in Drupal 7.x before
7.24 allows remote attackers to redirect users to arbitrary web sites
and conduct phishing attacks via unspecified vectors.
|
| CVE-2013-6388 |
Cross-site scripting (XSS) vulnerability in the Color module in Drupal
7.x before 7.24 allows remote attackers to inject arbitrary web script
or HTML via vectors related to CSS.
|
| CVE-2013-6387 |
Cross-site scripting (XSS) vulnerability in the Image module in Drupal
7.x before 7.24 allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via the description
field.
|
| CVE-2013-6386 |
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand
function to generate random numbers, which uses predictable seeds and
allows remote attackers to predict security strings and bypass
intended restrictions via a brute force attack.
|
| CVE-2013-6385 |
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used
with unspecified third-party modules, performs form validation even
when CSRF validation has failed, which might allow remote attackers to
trigger application-specific impacts such as arbitrary code execution
via application-specific vectors.
|
| CVE-2013-5965 |
The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal
does not properly implement the hook_query_alter function, which might
allow remote attackers to obtain sensitive information by reading a
node listing.
|
| CVE-2013-5964 |
Cross-site scripting (XSS) vulnerability in the administration page in
the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote
authenticated users with the "Administer flags" permission to inject
arbitrary web script or HTML via the flag title.
|
| CVE-2013-5938 |
Cross-site scripting (XSS) vulnerability in the Click2Sell Suite
module 6.x-1.x for Drupal allows remote attackers to inject arbitrary
web script or HTML via a confirmation form.
|
| CVE-2013-5937 |
Cross-site request forgery (CSRF) vulnerability in the Click2Sell
Suite module 6.x-1.x for Drupal allows remote attackers to hijack the
authentication of administrators for requests that delete database
information via vectors involving the Drupal Form API.
|
| CVE-2013-5315 |
Cross-site scripting (XSS) vulnerability in the Resource Manager in
the MEE submodule (mee.module) in the Scald module 6.x-1.x before
6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote
attackers to inject arbitrary web script or HTML via the atom title, a
different vector than CVE-2013-4174.
|
| CVE-2013-4599 |
The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2
for Drupal, when the "delay misery" configuration is set to a high
value, allows remote attackers to cause a denial of service (process
consumption) via multiple requests.
|
| CVE-2013-4598 |
The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for
Drupal does not properly check permission, which allows remote
attackers to access the configuration pages via unspecified vectors.
|
| CVE-2013-4597 |
The Revisioning module 7.x-1.x before 7.x-1.6 for Drupal does not
properly check node access permissions for content marked unpublished
by the Scheduled module, which allows remote authenticated users to
obtain sensitive information via unspecified vectors.
|
| CVE-2013-4596 |
The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not
properly check permissions, which allows remote attackers to bypass
access restrictions via a node listing.
|
| CVE-2013-4595 |
The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not
properly match URLs, which causes HTTP to be used instead of HTTPS and
makes it easier for remote attackers to obtain sensitive information
via a crafted web page.
|
| CVE-2013-4594 |
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does
not restrict access by anonymous users, which allows remote anonymous
users to use the payment of other anonymous users when submitting a
form that requires payment.
|
| CVE-2013-4552 |
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for
simpleSAMLphp allows remote attackers to authenticate as an arbitrary
user via the user name (uid) in a cookie.
|
| CVE-2013-4504 |
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote
attackers to read arbitrary node comments via a crafted URL.
|
| CVE-2013-4503 |
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper
module for Drupal allows remote authenticated users with the
"administer taxonomy" permission to inject arbitrary web script or
HTML via vectors related to options.
|
| CVE-2013-4502 |
The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before
7.x-1.9 for Drupal does not properly check file permissions, which
allows remote authenticated users to read arbitrary files by attaching
a file.
|
| CVE-2013-4501 |
The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal
allows remote attackers to obtain sensitive quiz results via
unspecified vectors.
|
| CVE-2013-4500 |
The Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote
authenticated users with the "view any quiz results" or "view results
for own quiz" permission to delete arbitrary results via the delete
option.
|
| CVE-2013-4499 |
Cross-site scripting (XSS) vulnerability in the Bean module 7.x-1.x
before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary
web script or HTML via the bean title.
|
| CVE-2013-4498 |
The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7
for Drupal does not properly delete organic group group spaces content
when using the option to move to a new group, which causes the content
to be "orphaned" and allows remote authenticated users with the
"access content" permission to obtain sensitive information via
vectors involving a rebuild access for the site or content.
|
| CVE-2013-4447 |
Cross-site scripting (XSS) vulnerability in the API in the Simplenews
module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal
allows remote attackers to inject arbitrary web script or HTML via an
email address.
|
| CVE-2013-4446 |
The _json_decode function in plugins/context_reaction_block.inc in the
Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for
Drupal, when using a version of PHP that does not support the
json_decode function, allows remote attackers to execute arbitrary PHP
code via unspecified vectors related to Ajax operations, possibly
involving eval injection.
|
| CVE-2013-4445 |
The json rendering functionality in the Context module 6.x-2.x before
6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token
scheme to restrict access to blocks, which makes it easier for remote
authenticated users to guess the access token for a block by
leveraging the token from a block to which the user has access.
|
| CVE-2013-4406 |
The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2,
and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block
permissions, which allows remote attackers to obtain sensitive
information by reading a Quick Tab.
|
| CVE-2013-4384 |
Cross-site scripting (XSS) vulnerability in Google Site Search module
6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10 for Drupal allows
remote attackers to inject arbitrary web script or HTML by causing
crafted data to be returned by the Google API.
|
| CVE-2013-4383 |
Cross-site scripting (XSS) vulnerability in the jQuery Countdown
module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated
users with the "access administration pages" permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-4380 |
Cross-site scripting (XSS) vulnerability in the MediaFront module
6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before
7.x-2.1 for Drupal allows remote authenticated users with the
"administer mediafront" permission to inject arbitrary web script or
HTML via the preset settings.
|
| CVE-2013-4379 |
The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal
allows remote attackers to bypass intended access restrictions for a
poll via a direct request to the node's URL instead of the hashed URL.
|
| CVE-2013-4337 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5965. Reason:
This candidate is a duplicate of CVE-2013-5965. Notes: All CVE users
should reference CVE-2013-5965 instead of this candidate. All
references and descriptions in this candidate have been removed to
prevent accidental usage.
|
| CVE-2013-4274 |
Cross-site scripting (XSS) vulnerability in the
password_policy_admin_view function in password_policy.admin.inc in
the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before
7.x-1.5 for Drupal allows remote authenticated users with the
"Administer policies" permission to inject arbitrary web script or
HTML via the "Password Expiration Warning" field to the
admin/config/people/password_policy/add page.
|
| CVE-2013-4273 |
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not
properly restrict access to node comments, which allows remote
authenticated users to read the comments via unspecified vectors.
NOTE: this identifier was SPLIT per ADT5 due to different researcher
organizations. CVE-2013-7391 was assigned for the View vector.
|
| CVE-2013-4272 |
The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x
before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the
debugging level is set to 5 or 6, logs the content of submitted forms,
which allows context-dependent users to obtain sensitive information
such as usernames and passwords by reading the log file.
|
| CVE-2013-4230 |
The mm_webform submodule in the Monster Menus module 6.x-6.x before
6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly
restrict access to webform submissions, which allows remote
authenticated users with the "Who can read data submitted to this
webform" permission to delete arbitrary submissions via unspecified
vectors.
|
| CVE-2013-4229 |
Cross-site scripting (XSS) vulnerability in the Monster Menus module
7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users
with permissions to add pages to inject arbitrary web script or HTML
via a title in the page settings.
|
| CVE-2013-4178 |
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and
7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain
access by replaying the username, password, and one-time password
(OTP).
|
| CVE-2013-4177 |
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and
7.x-1.x before 7.x-1.4 for Drupal does not properly identify user
account names, which might allow remote attackers to bypass the
two-factor authentication requirement via unspecified vectors.
|
| CVE-2013-4174 |
Multiple cross-site scripting (XSS) vulnerabilities in the Scald
module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to
inject arbitrary web script or HTML via the (1) flash_uri, (2)
flash_width, or (3) flash_height in the scald_flash_scald_prerender
function in providers/scald_flash/scald_flash.module; or the (4)
caption in the scald_image_scald_prerender function in
providers/scald_image/scald_image.module.
|
| CVE-2013-4140 |
Cross-site scripting (XSS) vulnerability in the TinyBox (Simple
Splash) module before 7.x-2.2 for Drupal allows remote authenticated
users with the "administer tinybox" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-4139 |
The Stage File Proxy module 7.x-1.x before 7.x-1.4 for Drupal allows
remote attackers to cause a denial of service (file operations
performance degradation and failure) via a large number of requests.
|
| CVE-2013-4138 |
Cross-site scripting (XSS) vulnerability in the Hatch theme 7.x-1.x
before 7.x-1.4 for Drupal allows remote authenticated users with the
"Administer content," "Create new article," or "Edit any article type
content" permission to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2013-2715 |
Cross-site scripting (XSS) vulnerability in the admin view in the
Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal
allows remote authenticated users with certain permissions to inject
arbitrary web script or HTML via a crafted field name.
|
| CVE-2013-2247 |
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and
7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to
the modal content callback, which allows remote attackers to obtain
unspecified access to the permissions edit form.
|
| CVE-2013-2197 |
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before
7.x-1.3 for Drupal, when using the login delay option, allows remote
attackers to cause a denial of service (CPU consumption) via a large
number of failed login attempts.
|
| CVE-2013-2177 |
Cross-site scripting (XSS) vulnerability in the Display Suite module
7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows
remote authenticated users with certain permissions to inject
arbitrary web script or HTML via an entity bundle label.
|
| CVE-2013-2158 |
Cross-site request forgery (CSRF) vulnerability in the Services module
6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers
to hijack the authentication of unspecified victims via unknown
vectors.
|
| CVE-2013-2129 |
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x
before 6.x-3.19 for Drupal allows remote authenticated users with the
"edit own webform content" or "edit all webform content" permissions
to inject arbitrary web script or HTML via a component label.
|
| CVE-2013-2123 |
The Node access user reference module 6.x-3.x before 6.x-3.5 and
7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access
to content containing a user reference field when the author
update/delete grants are enabled and the author's user account is
deleted, which allows remote attackers to modify the content via
unspecified vectors.
|
| CVE-2013-2122 |
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not
properly restrict access to comments, which allows remote
authenticated users with the "edit comments" permission to edit
arbitrary comments of other users via unspecified vectors.
|
| CVE-2013-2036 |
Cross-site scripting (XSS) vulnerability in the Filebrowser module
6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
"lists of files."
|
| CVE-2013-1972 |
Cross-site request forgery (CSRF) vulnerability in the elFinder file
manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for
Drupal allows remote attackers to hijack the authentication of
unspecified victims to create, modify, or delete files via unknown
vectors.
|
| CVE-2013-1971 |
Cross-site scripting (XSS) vulnerability in the MP3 Player module for
Drupal 6.x allows remote authenticated users with certain permissions
to inject arbitrary web script or HTML via the file name of a MP3
file.
|
| CVE-2013-1946 |
The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and
7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled
and anonymous users are assigned RESTWS permissions, allows remote
attackers to cause a denial of service via a GET request with an HTTP
Accept header set to a non-HTML type, which can "interfere with
Drupal's page cache."
|
| CVE-2013-1925 |
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal
does not properly restrict node access, which allows remote
authenticated users with the "access content" permission to read
restricted node titles via an autocomplete list.
|
| CVE-2013-1908 |
The Commons Wikis module before 7.x-3.1 for Drupal, as used in the
Commons module before 7.x-3.1, does not properly restrict access to
groups, which allows remote attackers to post arbitrary content to
groups via unspecified vectors.
|
| CVE-2013-1907 |
The Commons Group module before 7.x-3.1 for Drupal, as used in the
Commons module before 7.x-3.1, does not properly restrict access to
groups, which allows remote attackers to post arbitrary content to
groups via unspecified vectors.
|
| CVE-2013-1906 |
Cross-site scripting (XSS) vulnerability in the Rules module 7.x-2.x
before 7.x-2.3 for Drupal allows remote authenticated users with the
"administer rules" permission to inject arbitrary web script or HTML
via a rule tag.
|
| CVE-2013-1905 |
Cross-site scripting (XSS) vulnerability in the Zero Point theme
7.x-1.x before 7.x-1.9 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1887 |
Multiple cross-site scripting (XSS) vulnerabilities in the Views
module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via certain view configuration fields.
|
| CVE-2013-1859 |
The Node Parameter Control module 6.x-1.x for Drupal does not properly
restrict access to the configuration options, which allows remote
attackers to read and edit configuration options via unspecified
vectors.
|
| CVE-2013-1787 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Simple Corporate theme before 7.x-1.4 for Drupal allows remote
authenticated users with the administer themes permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1786 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Company theme before 7.x-1.4 for Drupal allows remote authenticated
users with the administer themes permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1785 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Premium Responsive theme before 7.x-1.6 for Drupal allows remote
authenticated users with the administer themes permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1784 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Clean Theme before 7.x-1.3 for Drupal allows remote authenticated
users with the administer themes permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1783 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in
page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal
allows remote authenticated users with the administer themes
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2013-1782 |
Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme
7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users
with the administer themes permission to inject arbitrary web script
or HTML via vectors related to social icons.
|
| CVE-2013-1781 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Professional theme before 7.x-1.4 for Drupal allows remote
authenticated users with the administer themes permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2013-1780 |
Cross-site scripting (XSS) vulnerability in the Best Responsive Theme
7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users
with the administer themes permission to inject arbitrary web script
or HTML via vectors related to social icons.
|
| CVE-2013-1779 |
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the
Fresh theme before 7.x-1.4 for Drupal allows remote authenticated
users with the administer themes permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-1778 |
Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x
before 7.x-1.2 for Drupal allows remote authenticated users with the
administer themes permission to inject arbitrary web script or HTML
via vectors related to social icons.
|
| CVE-2013-1393 |
Cross-site scripting (XSS) vulnerability in the CurvyCorners module
6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with
the "administer curvycorners" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2013-0325 |
Multiple cross-site scripting (XSS) vulnerabilities in the Varnish
module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for
Drupal allow remote attackers to inject arbitrary web script or HTML
via crafted a (1) Watchdog message or (2) admin setting.
|
| CVE-2013-0324 |
Cross-site scripting (XSS) vulnerability in the Rendered links
formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for
Drupal allows remote authenticated users with the "Administer menus
and menu items" permission to inject arbitrary web script or HTML via
the menu link title.
|
| CVE-2013-0323 |
Cross-site scripting (XSS) vulnerability in the Display Suite module
7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows
remote attackers to inject arbitrary web script or HTML via the author
field.
|
| CVE-2013-0322 |
Cross-site scripting (XSS) vulnerability in Views in the Ubercart
module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to
inject arbitrary web script or HTML via the full name field.
|
| CVE-2013-0321 |
Cross-site scripting (XSS) vulnerability in Views in the Ubercart
Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote
attackers to inject arbitrary web script or HTML via the full name
field.
|
| CVE-2013-0320 |
Cross-site request forgery (CSRF) vulnerability in the Taxonomy
Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x
before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the
authentication of users with 'administer taxonomy' permissions via
unspecified vectors.
|
| CVE-2013-0319 |
Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module
6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the Yandex.Metrica service data.
|
| CVE-2013-0318 |
The admin page in the Banckle Chat module for Drupal does not properly
restrict access, which allows remote attackers to bypass intended
restrictions via unspecified vectors.
|
| CVE-2013-0317 |
Cross-site scripting (XSS) vulnerability in the Manager Change for
Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for
Drupal might allow remote attackers to inject arbitrary web script or
HTML via the username in the new manager autocomplete field.
|
| CVE-2013-0316 |
The Image module in Drupal 7.x before 7.20 allows remote attackers to
cause a denial of service (CPU and disk space consumption) via a large
number of new derivative requests.
|
| CVE-2013-0260 |
Unspecified vulnerability in the Drush Debian Packaging module for
Drupal allows local users to obtain database credentials via unknown
vectors.
|
| CVE-2013-0259 |
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x
before 7.x-1.1 for Drupal allows remote authenticated users with
administer or edit boxes permissions to inject arbitrary web script or
HTML via the subject parameter.
|
| CVE-2013-0258 |
The Google Authenticator login (ga_login) module 7.x before 7.x-1.3
for Drupal, when multi-factor authentication is enabled, allows remote
attackers to bypass authentication for accounts without an associated
Google Authenticator token by logging in with the username.
|
| CVE-2013-0257 |
The email2image module 6.x-1.x and 6.x-2.x for Drupal does not
properly restrict access to nodes, which allows remote attackers to
read images of user email addresses and email fields.
|
| CVE-2013-0246 |
The Image module in Drupal 7.x before 7.19, when a private file system
is used, does not properly restrict access to derivative images, which
allows remote attackers to read derivative images of otherwise
restricted images via unspecified vectors.
|
| CVE-2013-0245 |
The printer friendly version functionality in the Book module in
Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict
access to node that are part of a book outline, which allows remote
authenticated users with the "access printer-friendly version"
permission to read node titles and possibly node content via
unspecified vectors.
|
| CVE-2013-0244 |
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and
7.x before 7.19, when running with older versions of jQuery that are
vulnerable to CVE-2011-4969, allows remote attackers to inject
arbitrary web script or HTML via vectors involving unspecified
Javascript functions that are used to select DOM elements.
|
| CVE-2013-0227 |
Cross-site scripting (XSS) vulnerability in the Search API Sorts
module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated
users with certain roles to inject arbitrary web script or HTML via
unspecified field labels.
|
| CVE-2013-0226 |
The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal
does not properly check node restrictions, which allows (1) remote
authenticated users with the "view shortcuts" permission to read nodes
or (2) remote authenticated users with the "admin shortcuts"
permission to read, edit, or delete nodes via unspecified vectors.
|
| CVE-2013-0225 |
Cross-site scripting (XSS) vulnerability in the User Relationships
module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for
Drupal allows remote authenticated users with the "administer user
relationships" permission to inject arbitrary web script or HTML via a
relationship name.
|
| CVE-2013-0224 |
The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the
FFmpeg transcoder, allows local users to execute arbitrary PHP code by
modifying a temporary PHP file.
|
| CVE-2013-0207 |
Cross-site request forgery (CSRF) vulnerability in the Mark Complete
module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to
hijack the authentication of unspecified victims via unknown vectors.
|
| CVE-2013-0206 |
Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x
before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote
authenticated users with the "administer CSS" permissions to execute
arbitrary code by uploading a file with an executable extension, then
accessing it via a direct request to the file in an unspecified
directory.
|
| CVE-2013-0205 |
Cross-site request forgery (CSRF) vulnerability in the RESTful Web
Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before
7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the
authentication of arbitrary users via unknown vectors.
|
| CVE-2013-0182 |
The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly
restrict access to payments, which allows remote attackers to read
arbitrary payments.
|
| CVE-2013-0181 |
Cross-site scripting (XSS) vulnerability in Views in the Search API
(search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using
certain backends and facets, allows remote attackers to inject
arbitrary web script or HTML via unspecified input, which is returned
in an error message.
|
| CVE-2012-6645 |
Cross-site scripting (XSS) vulnerability in the autocomplete
functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x,
and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers
to inject arbitrary web script or HTML via the title of a node, a
different vulnerability than CVE-2012-1561.
|
| CVE-2012-6583 |
Cross-site scripting (XSS) vulnerability in the Imagemenu module
6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users
with the "administer imagemenu" permission to inject arbitrary web
script or HTML via an image file name.
|
| CVE-2012-6582 |
Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x
before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain
remote attackers to inject arbitrary web script or HTML via a
stopforumspam.com API response, which is logged by the watchdog.
|
| CVE-2012-6576 |
Cross-site scripting (XSS) vulnerability in the PRH Search module
7.x-1.x before 7.x-1.1 for Drupal allows remote attackers from certain
sources to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6575 |
Cross-site scripting (XSS) vulnerability in the Exposed Filter Data
module 6.x-1.x before 6.x-1.2 for Drupal allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-6574 |
Cross-site scripting (XSS) vulnerability in the Fonecta verify module
7.x-1.x before 7.x-1.6 for Drupal allows remote attackers from certain
sources to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-6573 |
Cross-site scripting (XSS) vulnerability in the Apache Solr
Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3
for Drupal allows remote attackers to inject arbitrary web script or
HTML via vectors involving autocomplete results.
|
| CVE-2012-6572 |
Cross-site scripting (XSS) vulnerability in the
phptemplate_preprocess_node function in template.php in the Inf08
theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated
users with the "administer taxonomy" permission to inject arbitrary
web script or HTML via a taxonomy vocabulary name.
|
| CVE-2012-6065 |
The OM Maximenu module 6.x-1.43 and earlier for Drupal, when the
"Title has PHP" option is enabled, allows remote authenticated users
with the "Administer OM Maximenu" permission to execute arbitrary PHP
code via a "Link Title," a different vulnerability than CVE-2012-5553.
|
| CVE-2012-5705 |
Cross-site scripting (XSS) vulnerability in the settings page
(admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before
6.x-1.8 for Drupal allows remote authenticated users with the
"administer hotblocks" permission to inject arbitrary web script or
HTML via the "block names."
|
| CVE-2012-5704 |
The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote
authenticated users with the "administer hotblocks" permission to
cause a denial of service (infinite loop and time out) via a block
that references itself.
|
| CVE-2012-5655 |
The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before
7.x-3.0-beta6 for Drupal does not properly restrict access to block
content, which allows remote attackers to obtain sensitive information
via a crafted request.
|
| CVE-2012-5654 |
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when
configured to automatically generate description meta tags from node
text, does not properly filter node content when creating tags, which
might allow remote attackers to obtain sensitive information by
reading the (1) description, (2) dc.description or (3) og:description
meta tags.
|
| CVE-2012-5653 |
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18
allows remote authenticated users to bypass the protection mechanism
and execute arbitrary PHP code via a null byte in a file name.
|
| CVE-2012-5652 |
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive
information about uploaded files via a (1) RSS feed or (2) search
result.
|
| CVE-2012-5651 |
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for
blocked users, which might allow remote attackers to obtain sensitive
information by reading the search results.
|
| CVE-2012-5591 |
Cross-site scripting (XSS) vulnerability in the Zero Point module
6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows
remote attackers to inject arbitrary web script or HTML via the path
aliases.
|
| CVE-2012-5590 |
SQL injection vulnerability in the Webmail Plus module for Drupal
allows remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2012-5589 |
The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7
for Drupal does not properly check node permissions when generating an
in-content link, which allows remote authenticated users with
text-editing permissions to read arbitrary node titles via a generated
link.
|
| CVE-2012-5588 |
The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a
field permission module and the field contact field formatter is set
to the full or teaser display mode, does not properly check
permissions, which allows remote attackers to email the stored address
via unspecified vectors.
|
| CVE-2012-5587 |
Cross-site scripting (XSS) vulnerability in the Email Field module
6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the mailto link.
|
| CVE-2012-5586 |
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3
for Drupal allows remote authenticated users with the "access user
profiles" permission to access arbitrary users' emails via vectors
related to the "user index method" and "the path to the user
resource."
|
| CVE-2012-5585 |
Cross-site scripting (XSS) vulnerability in the Mixpanel module
6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users
with the "access administration pages" permission to inject arbitrary
web script or HTML via the Maxpanel token.
|
| CVE-2012-5584 |
The Table of Contents module 6.x-3.x before 6.x-3.8 for Drupal does
not properly check node permissions, which allows remote attackers to
read a node's headers by accessing a table of contents block.
|
| CVE-2012-5569 |
Multiple cross-site scripting (XSS) vulnerabilities in the Basic
webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote
attackers to inject arbitrary web script or HTML via a (1) page title
or (2) crafted email message.
|
| CVE-2012-5559 |
Cross-site scripting (XSS) vulnerability in the page manager node view
task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10
for Drupal allows remote authenticated users with permissions to
submit or edit nodes to inject arbitrary web script or HTML via the
page title.
|
| CVE-2012-5557 |
The User Read-Only module 6.x-1.x before 6.x-1.4 and 7.x-1.x before
7.x-1.4 for Drupal, does not properly assign roles when there are more
than three roles on the site and certain unspecified configurations,
which might allow remote authenticated users to gain privileges by
performing certain operations, as demonstrated by changing a password.
|
| CVE-2012-5556 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.1 and
7.x-2.x before 7.x-2.0-alpha3 for Drupal allow remote attackers to
hijack the authentication of arbitrary users via unknown vectors.
|
| CVE-2012-5554 |
The default configuration for the Webform CiviCRM Integration module
7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which
allows remote attackers to obtain contact information by reading
webforms.
|
| CVE-2012-5553 |
Multiple cross-site scripting (XSS) vulnerabilities in the OM Maximenu
module 6.x-1.x before 6.x-1.44 and 7.x-1.x before 7.x-1.44 for Drupal
allow remote authenticated users with the "administer OM Maximenu"
permission to inject arbitrary web script or HTML via the (1) Menu
Title (2) Link Title, (3) Path Query, (4) Anchor, or (5) vocabulary
names.
|
| CVE-2012-5552 |
The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before
7.x-1.3 for Drupal allows remote attackers to obtain password hashes
by sniffing the network, related to "client-side password history
checks."
|
| CVE-2012-5551 |
Multiple cross-site scripting (XSS) vulnerabilities in the MailChimp
module 7.x-2.x before 7.x-2.7 for Drupal allow remote attackers to
inject arbitrary web script or HTML via vectors related to (1) a
predictable "webhook URL key" and (2) improper sanitization of
"Webhook variables from POST requests."
|
| CVE-2012-5550 |
SQL injection vulnerability in the Time Spent module 6.x and 7.x for
Drupal allows remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2012-5549 |
Cross-site request forgery (CSRF) vulnerability in the Time Spent
module 6.x and 7.x for Drupal allows remote attackers to hijack the
authentication of unspecified victims via unknown vectors.
|
| CVE-2012-5548 |
Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x
and 7.x for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-5547 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Search API module 7.x-1.x before 7.x-1.3 for Drupal allow remote
attackers to hijack the authentication of administrators for requests
that (1) enable a server via a server action or (2) enable a search
index via an enable index action.
|
| CVE-2012-5546 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This
identifier was publicly assigned by its CNA to information that was
incorrectly specified due to a typo. Notes: none.
|
| CVE-2012-5545 |
Multiple cross-site scripting (XSS) vulnerabilities in the ShareThis
module 7.x-2.x before 7.x-2.5 for Drupal allow remote authenticated
users with the "administer sharethis" permission to inject arbitrary
web script or HTML via unspecified vectors related to "JavaScript
settings."
|
| CVE-2012-5544 |
The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote
authenticated users to obtain password reset links by reading the logs
in the Mandrill dashboard.
|
| CVE-2012-5543 |
The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a
field is mapped to the node's author, does not properly check
permissions, which allows remote attackers to create arbitrary nodes
via a crafted source feed.
|
| CVE-2012-5542 |
Cross-site request forgery (CSRF) vulnerability in the Commerce Extra
Panes module 7.x-1.x before 7.x-1.1 in Drupal allows remote attackers
to hijack the authentication of administrators for requests that
enable or disable a Commerce extra panes pane via unspecified vectors
related to "the link to reorder items."
|
| CVE-2012-5541 |
Cross-site scripting (XSS) vulnerability in the Twitter Pull module
6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.0-rc3 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to "data coming from Twitter."
|
| CVE-2012-5540 |
Multiple cross-site scripting (XSS) vulnerabilities in the Hostip
module 6.x-2.x before 6.x-2.2 and 7.x-2.x before 7.x-2.2 for Drupal
allow remote attackers with control of hostip.info to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-5539 |
The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does
not properly maintain pending group memberships, which allows remote
authenticated users to post to arbitrary groups by modifying their own
account while a pending membership is waiting to be approved.
|
| CVE-2012-5538 |
Cross-site scripting (XSS) vulnerability in the FileField Sources
module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal,
when the field has "Reference existing" source enabled, allows remote
authenticated users to inject arbitrary web script or HTML via the
filename of an uploaded file.
|
| CVE-2012-5537 |
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal
allows remote authenticated users with the "send scheduled
newsletters" permission to inject arbitrary PHP code into the
scheduling form, which is later executed by cron.
|
| CVE-2012-5233 |
Cross-site scripting (XSS) vulnerability in the stickynote module
before 7.x-1.1 for Drupal allows remote authenticated users with edit
stickynotes privileges to inject arbitrary web script or HTML via
unspecified vecotrs.
|
| CVE-2012-5007 |
The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote
attackers to write to arbitrary PDF files via unspecified vectors
related to the fillpdf_merge_pdf function and incorrect arguments, a
different vulnerability than CVE-2012-1625. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-4554 |
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID
servers to read arbitrary files via a crafted DOCTYPE declaration in
an XRDS file.
|
| CVE-2012-4553 |
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive
information and possibly re-install Drupal and execute arbitrary PHP
code via an external database server, related to "transient
conditions."
|
| CVE-2012-4500 |
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows
remote authenticated users with the "access announcements" permission
to bypass node access restrictions and possibly have other unspecified
impact.
|
| CVE-2012-4499 |
The contact formatter page in the Email Field module 6.x-1.x before
6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers
to email the stored address in the entity via unspecified vectors.
|
| CVE-2012-4498 |
The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not
properly restrict access to the "Campaign" content type, which might
allow remote attackers to bypass access restrictions and possibly have
other unspecified impact.
|
| CVE-2012-4497 |
Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in
the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the "administer themes" permission to
inject arbitrary web script or HTML via a slide URL.
|
| CVE-2012-4496 |
Cross-site scripting (XSS) vulnerability in the Custom Publishing
Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote
authenticated users with the "administer nodes" permission to inject
arbitrary web script or HTML via the status labels parameter.
|
| CVE-2012-4495 |
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not
properly restrict access to files outside Drupal's publish files
directory, which allows remote authenticated users to send arbitrary
files as attachments.
|
| CVE-2012-4494 |
The Shibboleth authentication module 7.x-4.0 for Drupal does not
properly check the active status of users, which allows remote blocked
users to access bypass intended access restrictions and possibly have
other impacts by logging in.
|
| CVE-2012-4493 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for
Drupal allows remote authenticated users with the "administer better
revisions" permission to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4492 |
Multiple cross-site scripting (XSS) vulnerabilities in the Shorten
URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for
Drupal allow remote authenticated users with certain permissions to
inject arbitrary web script or HTML via unspecified vectors to the (1)
report or (2) Custom Services List page.
|
| CVE-2012-4491 |
The Monthly Archive by Node Type module 6.x for Drupal does not
properly check permissions defined by node_access modules, which
allows remote attackers to access restricted nodes via unspecified
vectors.
|
| CVE-2012-4490 |
Multiple cross-site scripting (XSS) vulnerabilities in the Excluded
Users module 6.x-1.x before 6.x-1.1 for Drupal allow remote attackers
to inject arbitrary web script or HTML via a (1) user name or (2)
email address.
|
| CVE-2012-4489 |
Open redirect vulnerability in the securelogin_secure_redirect
function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal
allows remote attackers to redirect users to arbitrary web sites and
conduct phishing attacks via a URL in the q parameter.
|
| CVE-2012-4488 |
The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1
for Drupal does not properly check user or node access permissions,
which allows remote attackers to read node or user results via the
location search page.
|
| CVE-2012-4487 |
The Subuser module before 6.x-1.8 for Drupal does not properly check
"switch subuser" permissions, which allows remote authenticated parent
users to change their role by switching to a subuser they created.
|
| CVE-2012-4486 |
Cross-site request forgery (CSRF) vulnerability in the Subuser module
before 6.x-1.8 for Drupal allows remote attackers to hijack the
authentication of arbitrary users for requests that switch the user to
a subuser via unspecified vectors.
|
| CVE-2012-4485 |
Multiple cross-site scripting (XSS) vulnerabilities in the
galleryformatter_field_formatter_view functiuon in
galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2
for Drupal allow remote authenticated users with permissions to create
a node or entity to inject arbitrary web script or HTML via the (1)
title or (2) alt parameter.
|
| CVE-2012-4484 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in the Campaign Monitor module before 6.x-2.5 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-4483 |
The commons_discussion_views_default_views function in
modules/features/commons_discussion/commons_discussion.views_default.inc
in the Drupal Commons module 6.x-2.x before 6.x-2.8 for Drupal does
not properly enforce intended node access restrictions, which might
allow remote attackers to obtain sensitive information via the recent
comments listing.
|
| CVE-2012-4482 |
The Ubercart SecureTrading Payment Method module 6.x for Drupal does
not properly verify payment notification information, which allows
remote attackers to purchase an item without paying via unspecified
vectors.
|
| CVE-2012-4479 |
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for
Drupal allows remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2012-4478 |
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop
Gallery module 6.x for Drupal allows remote attackers to hijack the
authentication of administrators.
|
| CVE-2012-4477 |
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for
Drupal allows remote attackers to bypass access restrictions via
unknown attack vectors.
|
| CVE-2012-4476 |
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery
module 6.x for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-4475 |
The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and
7.x-1.x before 7.x-1.1 does not properly restrict access, which allows
remote attackers to edit an arbitrary user's questions and answers via
unspecified vectors.
|
| CVE-2012-4474 |
Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox
Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers
to inject arbitrary web script or HTML via unspecified parameters.
|
| CVE-2012-4473 |
The Restrict node page view module 7.x-1.x before 7.x-1.2 for Drupal
allows remote authenticated users with the "view any node page" or
"view any node {type} page" permission to access unpublished nodes via
a direct request.
|
| CVE-2012-4472 |
Unrestricted file upload vulnerability in upload.php in the Drag &
Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote
attackers to execute arbitrary PHP code by uploading a file with an
executable extension followed by a safe extension, then accessing it
via a direct request to the directory specified by the filedir
parameter.
|
| CVE-2012-4471 |
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does
not properly restrict access to the module admin page, which allows
remote attackers to disable an autocompletion or change the priority
order via unspecified vectors.
|
| CVE-2012-4470 |
The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not
properly check permissions when importing emails, which allows remote
comment authors to bypass access restrictions and possibly have other
unspecified impact.
|
| CVE-2012-4469 |
Cross-site scripting (XSS) vulnerability in the Hashcash module
6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when
"Log failed hashcash" is enabled, allows remote attackers to inject
arbitrary web script or HTML via an invalid token, which is not
properly handled when administrators use the Database logging module.
|
| CVE-2012-4468 |
Cross-site scripting (XSS) vulnerability in the Privatemsg module
7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via a user name in a private message.
|
| CVE-2012-3802 |
Unspecified vulnerability in the Post Affiliate Pro (PAP) module for
Drupal allows remote authenticated users to read the commissions of
other users via unknown attack vectors.
|
| CVE-2012-3801 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2704. Reason:
This candidate is a duplicate of CVE-2012-2704. Notes: All CVE users
should reference CVE-2012-2704 instead of this candidate. All
references and descriptions in this candidate have been removed to
prevent accidental usage.
|
| CVE-2012-3800 |
Cross-site scripting (XSS) vulnerability in og.js in the Organic
Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with
the Vertical Tabs module, allows remote authenticated users to inject
arbitrary web script or HTML via vectors related the group title.
|
| CVE-2012-3799 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote
attackers to hijack the authentication of administrators for requests
that (1) change workflows or (2) insert cross-site scripting (XSS)
sequences.
|
| CVE-2012-3798 |
The Janrain Capture module 6.x-1.0 and 7.x-1.0 for Drupal, when
creating a local user account, allows attackers to obtain part of the
initial input used to generate passwords, which makes it easier to
conduct brute force password guessing attacks.
|
| CVE-2012-2922 |
The request_path function in includes/bootstrap.inc in Drupal 7.14 and
earlier allows remote attackers to obtain sensitive information via
the q[] parameter to index.php, which reveals the installation path in
an error message.
|
| CVE-2012-2907 |
Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb
function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11
for Drupal, when set to append the content title to the breadcrumb,
allows remote attackers to inject arbitrary web script or HTML via the
content title in a breadcrumb.
|
| CVE-2012-2731 |
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the
PHP session id in the JavaScript settings array in page loads, which
might allow remote attackers to obtain sensitive information by
sniffing or reading the cache of the HTML of a webpage.
|
| CVE-2012-2730 |
The Protected Node module 6.x-1.x before 6.x-1.6 for Drupal does not
properly "protect node access when nodes are accessed outside of the
standard node view," which allows remote attackers to bypass intended
access restrictions.
|
| CVE-2012-2729 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote
attackers to hijack the authentication of administrators for requests
that (1) delete or (2) add a meta tag entry.
|
| CVE-2012-2728 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Node
Hierarchy module 6.x-1.x before 6.x-1.5 for Drupal allow remote
attackers to hijack the authentication of administrators for requests
that change a node hierarchy position via an (1) up or (2) down
action.
|
| CVE-2012-2727 |
Open redirect vulnerability in the Janrain Capture module 6.x-1.0 and
7.x-1.0 for Drupal, when synchronizing user data, allows remote
attackers to redirect users to arbitrary web sites and conduct
phishing attacks via a URL in the destination parameter.
|
| CVE-2012-2726 |
Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x
before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote
authenticated users with the "administer protest" permission to inject
arbitrary web script or HTML via the protest_body parameter.
|
| CVE-2012-2725 |
classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML
module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate
sources with the host white list, which allows remote authenticated
users to bypass intended access restrictions and conduct cross-site
scripting (XSS) attacks.
|
| CVE-2012-2723 |
Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x
before 7.x-1.2 for Drupal allows remote authenticated users with
maestro admin permissions to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2722 |
The node selection interface in the WYSIWYG editor (CKEditor) in the
Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0
for Drupal does not properly check permissions, which allows remote
attackers to bypass intended access restrictions and read node titles.
|
| CVE-2012-2721 |
The default views in the Organic Groups (OG) module 6.x-2.x before
6.x-2.4 for Drupal do not properly check permissions when all users
have the "access content" permission removed, which allows remote
attackers to bypass access restrictions and possibly have other
unspecified impact.
|
| CVE-2012-2720 |
The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for
Drupal does not properly revert user sessions, which might allow
remote attackers to perform requests with extra privileges.
|
| CVE-2012-2719 |
The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed
using multiple different browsers from the same IP address, causes
Internet Explorer sessions to "switch users" when uploading a file,
which has unspecified impact possibly involving file uploads to the
wrong user directory, aka "Session Management Vulnerability."
|
| CVE-2012-2718 |
SQL injection vulnerability in the Counter module for Drupal allows
remote attackers to execute arbitrary SQL commands via unspecified
vectors related to "recording visits."
|
| CVE-2012-2717 |
Multiple cross-site scripting (XSS) vulnerabilities in the Mobile
Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers
to inject arbitrary web script or HTML via the (1) Mobile URL field or
(2) Desktop URL field to the General configuration page, or the (3)
message to the Mobile Tools block message options.
|
| CVE-2012-2716 |
Cross-site request forgery (CSRF) vulnerability in the Comment
Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote
attackers to hijack the authentication of administrators for requests
that publish comments.
|
| CVE-2012-2715 |
Cross-site scripting (XSS) vulnerability in the themes_links function
in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via vectors related to class attributes in a list of links.
|
| CVE-2012-2713 |
Cross-site request forgery (CSRF) vulnerability in the BrowserID
(Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows
remote attackers to hijack the authentication of arbitrary users for
requests that login a user to another web site.
|
| CVE-2012-2712 |
Multiple cross-site scripting (XSS) vulnerabilities in the Search API
module 7.x-1.x before 7.x-1.1 for Drupal, when supporting manual entry
of field identifiers, allow remote attackers to inject arbitrary web
script or HTML via vectors related to thrown exceptions and logging
errors.
|
| CVE-2012-2711 |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy
List module 6.x-1.x before 6.x-1.4 for Drupal allow remote
authenticated users with create or edit taxonomy terms permissions to
inject arbitrary web script or HTML via vectors related to taxonomy
information.
|
| CVE-2012-2710 |
Cross-site scripting (XSS) vulnerability in the Zen module 6.x-1.x
before 6.x-1.1 for Drupal, when "Append the content title to the end
of the breadcrumb" is enabled, allows remote attackers to inject
arbitrary web script or HTML via the content title in a breadcrumb.
|
| CVE-2012-2709 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2907. Reason:
This candidate is a duplicate of CVE-2012-2907. Notes: All CVE users
should reference CVE-2012-2907 instead of this candidate. All
references and descriptions in this candidate have been removed to
prevent accidental usage.
|
| CVE-2012-2708 |
Cross-site scripting (XSS) vulnerability in the
_hosting_task_log_table function in
modules/hosting/task/hosting_task.module in the Hostmaster (Aegir)
module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via a Drush log message in a provision task log.
|
| CVE-2012-2707 |
The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does
not properly exit when users do not have access to package/task nodes,
which allows remote attackers to bypass intended access restrictions
and edit unauthorized nodes.
|
| CVE-2012-2706 |
Cross-site scripting (XSS) vulnerability in the Post Affiliate Pro
(PAP) module for Drupal allows remote attackers to inject arbitrary
web script or HTML via vectors related to user registration.
|
| CVE-2012-2705 |
The filter_titles function in the Smart Breadcrumb module 6.x-1.x
before 6.x-1.3 for Drupal does not properly convert a title to
plain-text, which allows remote authenticated users with create or
edit node permissions to conduct cross-site scripting (XSS) attacks
via the title parameter.
|
| CVE-2012-2704 |
The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not
properly restrict access to debug information, which allows remote
attackers to obtain sensitive site configuration information that is
specified by the $conf variable in settings.php.
|
| CVE-2012-2703 |
Cross-site scripting (XSS) vulnerability in the Advertisement module
6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the "$conf variable in settings.php."
|
| CVE-2012-2702 |
The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal
does not properly check access for product keys, which allows remote
attackers to read all unassigned product keys via certain conditions
related to the uid.
|
| CVE-2012-2701 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2341. Reason:
This candidate is a duplicate of CVE-2012-2341. Notes: All CVE users
should reference CVE-2012-2341 instead of this candidate. All
references and descriptions in this candidate have been removed to
prevent accidental usage.
|
| CVE-2012-2700 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2340. Reason:
This candidate is a duplicate of CVE-2012-2340. Notes: All CVE users
should reference CVE-2012-2340 instead of this candidate. All
references and descriptions in this candidate have been removed to
prevent accidental usage.
|
| CVE-2012-2699 |
** REJECT **
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2339. Reason:
This candidate is a duplicate of CVE-2012-2339. Notes: All CVE users
should reference CVE-2012-2339 instead of this candidate. All
references and descriptions in this candidate have been removed to
prevent accidental usage.
|
| CVE-2012-2341 |
Cross-site request forgery (CSRF) vulnerability in the Take Control
module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to
hijack the authentication of unspecified users for Ajax requests that
manipulate files.
|
| CVE-2012-2340 |
The Contact Forms module 7.x-1.x before 7.x-1.2 for Drupal does not
specify sufficiently restrictive permissions, which allows remote
authenticated users with the "access the site-wide contact form"
permission to modify the module settings via unspecified vectors.
|
| CVE-2012-2339 |
Cross-site scripting (XSS) vulnerability in the Glossary module
6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors related to
"taxonomy information."
|
| CVE-2012-2310 |
Cross-site scripting (XSS) vulnerability in the cctags module for
Drupal 6.x-1.x before 6.x-1.10 and 7.x-1.x before 7.x-1.10 allows
remote authenticated users with certain roles to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2309 |
Cross-site scripting (XSS) vulnerability in the Glossify Internal
Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote
authenticated users with certain roles to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2012-2308 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Grid :
Catalog module for Drupal 6.x-1.6 and earlier allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2307 |
Cross-site request forgery (CSRF) vulnerability in the Addressbook
module for Drupal 6.x-4.2 and earlier allows remote attackers to
hijack the authentication of unspecified victims via unknown vectors.
|
| CVE-2012-2306 |
SQL injection vulnerability in the Addressbook module for Drupal
6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL
commands via unspecified vectors.
|
| CVE-2012-2305 |
Cross-site request forgery (CSRF) vulnerability in the Node Gallery
module for Drupal 6.x-3.1 and earlier allows remote attackers to
hijack the authentication of certain users for requests that create
node galleries.
|
| CVE-2012-2304 |
The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an
entity access module, does not check permissions when searching for
entities, which allows remote attackers to obtain sensitive
information via unspecified vectors.
|
| CVE-2012-2303 |
The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce
permissions on non-object pages, which allows remote attackers to
obtain sensitive information and possibly have other impacts via
unspecified vectors to the (1) Spaces or (2) Spaces OG module.
|
| CVE-2012-2302 |
Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4
does not properly check the save location when archiving, which allows
remote attackers to obtain sensitive information via unspecified
vectors.
|
| CVE-2012-2301 |
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote
authenticated users with the "administer product classes" permission
to execute arbitrary PHP code via unspecified vectors.
|
| CVE-2012-2300 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart
module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal
allow remote authenticated users with the administer product classes
permission to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-2299 |
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1
for Drupal stores passwords for new customers in plaintext during
checkout, which allows local users to obtain sensitive information by
reading from the database.
|
| CVE-2012-2298 |
Multiple cross-site scripting (XSS) vulnerabilities in the RealName
module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to
inject arbitrary web script or HTML via vectors related to (1) "user
names in page titles" and (2) "autocomplete callbacks."
|
| CVE-2012-2297 |
Multiple cross-site scripting (XSS) vulnerabilities in the Creative
Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote
authenticated users with the administer creative commons permission to
inject arbitrary web script or HTML via the (1)
creativecommons_user_message or (2)
creativecommons_site_license_additional_text parameter.
|
| CVE-2012-2296 |
The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x
before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores user profile data
from Engage in session tables, which might allow remote attackers to
obtain sensitive information by leveraging a separate vulnerability.
|
| CVE-2012-2155 |
Cross-site request forgery (CSRF) vulnerability in the CDN2 Video
module 6.x for Drupal allows remote attackers to hijack the
authentication of unspecified victims via unknown vectors.
|
| CVE-2012-2154 |
Cross-site scripting (XSS) vulnerability in the CDN2 Video module 6.x
for Drupal allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-2153 |
Drupal 7.x before 7.14 does not properly restrict access to nodes in a
list when using a "contributed node access module," which allows
remote authenticated users with the "Access the content overview page"
permission to read all published nodes by accessing the admin/content
page.
|
| CVE-2012-2117 |
Cross-site scripting (XSS) vulnerability in the Gigya - Social
optimization module 6.x before 6.x-3.2 for Drupal allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-2116 |
Cross-site request forgery (CSRF) vulnerability in the Commerce
Reorder module before 7.x-1.1 for Drupal allows remote attackers to
hijack the authentication of arbitrary users for requests that add
items to the shopping cart.
|
| CVE-2012-2097 |
Cross-site request forgery (CSRF) vulnerability in the Autosave module
6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows
remote attackers to hijack the authentication of arbitrary users for
requests involving "submitting saved results to a node."
|
| CVE-2012-2096 |
The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not
properly validate voting data, which allows remote attackers to
manipulate voting averages via a negative value in the vote parameter.
|
| CVE-2012-2084 |
Cross-site scripting (XSS) vulnerability in the Printer, email and PDF
versions module 6.x-1.x before 6.x-1.15 and 7.x-1.x before 7.x-1.0 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors, probably the PATH_INFO.
|
| CVE-2012-2083 |
Cross-site scripting (XSS) vulnerability in the
fusion_core_preprocess_page function in fusion_core/template.php in
the Fusion module before 6.x-1.13 for Drupal allows remote attackers
to inject arbitrary web script or HTML via the q parameter.
|
| CVE-2012-2082 |
Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka
CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote
authenticated users with the post comments permission to inject
arbitrary web script or HTML via a user signature.
|
| CVE-2012-2081 |
The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does
not properly restrict access, which allows remote attackers to obtain
sensitive information such as private group titles via a request
through the Views module.
|
| CVE-2012-2080 |
Cross-site request forgery (CSRF) vulnerability in the Node Limit
Number module before 6.x-1.2 for Drupal allows remote attackers to
hijack the authentication of users with the administer node
limitnumber permission for requests that delete limits.
|
| CVE-2012-2077 |
Cross-site request forgery (CSRF) vulnerability in the ShareThis
module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to
hijack the authentication of users with administer sharethis
permissions via unknown vectors "outside of the Form API."
|
| CVE-2012-2076 |
Cross-site scripting (XSS) vulnerability in the administration forms
in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows
remote authenticated users with administer sharethis permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2075 |
Cross-site scripting (XSS) vulnerability in the Contact Save module
6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users
with the access site-wide contact form permission to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-2074 |
Unspecified vulnerability in certain default views in the Ubercart
Views module 6.x before 6.x-3.2 for Drupal allows remote attackers to
obtain sensitive information via unknown attack vectors.
|
| CVE-2012-2073 |
The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not
check for the "use PHP for settings" permission while importing
settings, which allows remote authenticated users with certain
permissions to execute arbitrary PHP code via unspecified vectors.
|
| CVE-2012-2072 |
Cross-site scripting (XSS) vulnerability in the Share Buttons
(AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote
authenticated users with the administer addtoany permission to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2071 |
Cross-site scripting (XSS) vulnerability in the Contact Forms module
6.x-1.x before 6.x-1.13 for Drupal when the core contact form is
enabled, allows remote authenticated users with the administer
site-wide contact form permission to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2012-2070 |
Cross-site scripting (XSS) vulnerability in the MultiBlock module
6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows
remote authenticated users with the administer blocks permission to
inject arbitrary web script or HTML via the block title.
|
| CVE-2012-2069 |
Cross-site request forgery (CSRF) vulnerability in the Wishlist module
6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows
remote attackers to hijack the authentication of arbitrary users for
requests that insert cross-site scripting (XSS) sequences via the (1)
wl_reveal or (2) q parameters.
|
| CVE-2012-2068 |
Multiple cross-site scripting (XSS) vulnerabilities in
fancy_slide.module in the Fancy Slide module before 6.x-2.7 for Drupal
allow remote authenticated users with the administer fancy_slide
permission to inject arbitrary web script or HTML via the (1)
node_title or (2) nodequeue_title parameter.
|
| CVE-2012-2067 |
Unspecified vulnerability in the CKeditor module 6.x-2.x before
6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x
before 7.x-1.7 for Drupal, when the core PHP module is enabled, allows
remote authenticated users or remote attackers to execute arbitrary
PHP code via the text parameter to a text filter. NOTE: some of these
details are obtained from third party information.
|
| CVE-2012-2066 |
Cross-site scripting (XSS) vulnerability in the FCKeditor module
6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9
and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated
users or remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2012-2065 |
Cross-site scripting (XSS) vulnerability in the Language Icons module
6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows
remote authenticated users with administer languages permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-2064 |
Cross-site scripting (XSS) vulnerability in
theme/views_lang_switch.theme.inc in the Views Language Switcher
module before 7.x-1.2 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the q parameter.
|
| CVE-2012-2063 |
The Slidebox module before 7.x-1.4 for Drupal does not properly check
permissions, which allows remote attackers to obtain sensitive
information via unspecified vectors.
|
| CVE-2012-2062 |
Open redirect vulnerability in the Redirecting click bouncer module
for Drupal allows remote attackers to redirect users to arbitrary web
sites and conduct phishing attacks via unspecified vectors.
|
| CVE-2012-2061 |
Cross-site request forgery (CSRF) vulnerability in the Admin tools
module for Drupal allows remote attackers to hijack the authentication
of unspecified victims via unknown vectors involving "not checking
tokens."
|
| CVE-2012-2060 |
Cross-site scripting (XSS) vulnerability in the Admin tools module for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-2059 |
Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker
module for Drupal allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-2058 |
The Ubercart Payflow module for Drupal does not use a secure token,
which allows remote attackers to forge payments via unspecified
vectors.
|
| CVE-2012-2057 |
Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk
Stock Updater module for Drupal allows remote attackers to hijack the
authentication of unspecified victims via unknown vectors related to
formAPI.
|
| CVE-2012-2056 |
Cross-site request forgery (CSRF) vulnerability in the Content Lock
module for Drupal allows remote attackers to hijack the authentication
of unspecified victims via unknown vectors.
|
| CVE-2012-1660 |
Multiple cross-site scripting (XSS) vulnerabilities in
components/select.inc in the Webform module 6.x-3.x before 6.x-3.17
and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)"
module is enabled, allow remote authenticated users with the create
webform content permission to inject arbitrary web script or HTML via
vectors related to (1) checkboxes or (2) radios.
|
| CVE-2012-1659 |
Cross-site scripting (XSS) vulnerability in the Node Recommendation
module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated
users with certain permissions to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-1658 |
Cross-site scripting (XSS) vulnerability in the Read More Link module
6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users
with the access administration pages permission to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2012-1657 |
Cross-site scripting (XSS) vulnerability in block_class.module in the
Block Class module before 7.x-1.1 for Drupal allows remote
authenticated users with certain permissions to inject arbitrary web
script or HTML via the class name.
|
| CVE-2012-1656 |
SQL injection vulnerability in the Multisite Search module 6.x-2.2 for
Drupal allows remote authenticated users with certain permissions to
execute arbitrary SQL commands via the Site table prefix field.
|
| CVE-2012-1655 |
Unspecified vulnerability in the UC PayDutchGroup / WeDeal payment
module 6.x-1.0 for Drupal allows remote authenticated users to obtain
account credentials via unknown attack vectors.
|
| CVE-2012-1654 |
Multiple cross-site scripting (XSS) vulnerabilities in the Data module
6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal
allow remote authenticated users with the administer data tables
permission to inject arbitrary web script or HTML via the title
parameter in (1) data.views.inc and (2) data_ui/data_ui.admin.inc.
|
| CVE-2012-1653 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Views
Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows
remote authenticated users to inject arbitrary web script or HTML via
unspecified vectors, related to "views pages."
|
| CVE-2012-1652 |
Cross-site scripting (XSS) vulnerability in the Hierarchical Select
module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated
users with administer taxonomy permissions to inject arbitrary web
script or HTML via unspecified vectors related to "the vocabulary's
help text."
|
| CVE-2012-1651 |
Cross-site scripting (XSS) vulnerability in the Submenu Tree module
before 6.x-1.5 for Drupal allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1650 |
The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access
content" permission instead of the "access ZipCart downloads"
permission when building archives, which allows remote authenticated
users with access content permission to bypass intended access
restrictions.
|
| CVE-2012-1649 |
Cool Aid module before 6.x-1.9 for Drupal does not enforce access
restrictions, which allows remote authenticated users with the
administer coolaid permission to modify arbitrary pages via
unspecified vectors.
|
| CVE-2012-1648 |
Cross-site scripting (XSS) vulnerability in the Cool Aid module before
6.x-1.9 for Drupal allows remote authenticated users with the
administer coolaid permission to inject arbitrary web script or HTML
via unspecified vectors.
|
| CVE-2012-1647 |
Multiple cross-site scripting (XSS) vulnerabilities in the "stand
alone PHP application for the OSM Player," as used in the MediaFront
module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal,
allow remote attackers to inject arbitrary web script or HTML via (1)
$_SERVER['HTTP_HOST'] or (2) $_SERVER['SCRIPT_NAME'] to
players/osmplayer/player/OSMPlayer.php, (3) playlist parameter to
players/osmplayer/player/getplaylist.php, and possibly other vectors
related to $_SESSION.
|
| CVE-2012-1646 |
Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module
6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote
authenticated users to inject arbitrary web script or HTML via the (1)
title parameter in faq.admin.inc or (2) detailed_question parameter in
faq.module.
|
| CVE-2012-1645 |
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin
Pull mode with the "Far Future expiration" option enabled, allows
remote attackers to read arbitrary PHP files via unspecified vectors,
as demonstrated by reading settings.php.
|
| CVE-2012-1644 |
The Organic Groups (OG) Vocabulary module 6.x-1.x before 6.x-1.2 for
Drupal allows remote authenticated users with certain administrator
permissions to modify the vocabularies of other groups via unspecified
vectors.
|
| CVE-2012-1643 |
The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does
not check the "administer permissions" permission, which allows remote
attackers to modify access permissions via unspecified vectors.
|
| CVE-2012-1642 |
includes/linkchecker.pages.inc in the Link checker module 6.x-2.x
before 6.x-2.5 for Drupal does not properly enforce access permissions
on broken links, which allows remote attackers to obtain sensitive
information via unspecified vectors.
|
| CVE-2012-1641 |
The finder_import function in the Finder module 6.x-1.x before
6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows
remote authenticated users with the administer finder permission to
execute arbitrary PHP code via admin/build/finder/import.
|
| CVE-2012-1640 |
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite
module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated
users with "administer managesite" permissions to inject arbitrary web
script or HTML via the title parameter when (1) adding or (2) updating
a category.
|
| CVE-2012-1639 |
Multiple cross-site scripting (XSS) vulnerabilities in
product/commerce_product.module in the Drupal Commerce module for
Drupal before 7.x-1.2 allow remote authenticated users to inject
arbitrary web script or HTML via the (1) sku or (2) title parameters.
|
| CVE-2012-1638 |
SQL injection vulnerability in the Search Autocomplete module before
7.x-2.1 for Drupal allows remote authenticated users with the "use
search_autocomplete" permission to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2012-1636 |
Cross-site request forgery (CSRF) vulnerability in the stickynote
module before 7.x-1.1 for Drupal allows remote attackers to hijack the
authentication of users for requests that delete stickynotes via
unspecified vectors.
|
| CVE-2012-1635 |
The hook_node_access function in the revisioning module 7.x-1.x before
7.x-1.3 for Drupal checks the permissions of the current user even
when it is called to check permissions of other users, which allows
remote attackers to bypass intended access restrictions, as
demonstrated when using the XML sitemap module to obtain sensitive
information about unpublished content.
|
| CVE-2012-1634 |
Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in
the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote
attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP
parameter for Blip.tv links.
|
| CVE-2012-1633 |
Cross-site request forgery (CSRF) vulnerability in the Password Policy
module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote
attackers to hijack the authentication of administrative users for
requests that unblock a user.
|
| CVE-2012-1632 |
Cross-site scripting (XSS) vulnerability in password_policy.admin.inc
in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for
Drupal allows remote authenticated users with administer policies
permissions to inject arbitrary web script or HTML via the name
parameter.
|
| CVE-2012-1631 |
Cross-site request forgery (CSRF) vulnerability in the Admin:hover
module for Drupal allows remote attackers to hijack the authentication
of administrators for requests that unpublish all nodes, and possibly
other actions, via unspecified vectors.
|
| CVE-2012-1630 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator
module for Drupal allows remote authenticated users with certain
permissions to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2012-1629 |
Cross-site scripting (XSS) vulnerability in the Taxotouch module for
Drupal allows remote authenticated users with certain permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2012-1628 |
Cross-site scripting (XSS) vulnerability in the SuperCron module for
Drupal allows remote authenticated users to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2012-1627 |
Cross-site scripting (XSS) vulnerability in vud_term.module in the
Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1
for Drupal allows remote authenticated users to inject arbitrary web
script or HTML via taxonomy terms.
|
| CVE-2012-1626 |
SQL injection vulnerability in the conversion form for Events in the
Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote
authenticated users with the "administer Date Tools" privilege to
execute arbitrary SQL commands via unspecified vectors.
|
| CVE-2012-1625 |
Eval injection vulnerability in the fillpdf_form_export_decode
function in fillpdf.admin.inc in the Fill PDF module 6.x-1.x before
6.x-1.16 and 7.x-1.x before 7.x-1.2 for Drupal allows remote
authenticated users with administer PDFs privileges to execute
arbitrary PHP code via unspecified vectors. NOTE: Some of these
details are obtained from third party information.
|
| CVE-2012-1624 |
Multiple cross-site scripting (XSS) vulnerabilities in the Lingotek
module 6.x-1.x before 6.x-1.40 for Drupal allow remote authenticated
users to inject arbitrary web script or HTML when (1) creating or (2)
editing page content.
|
| CVE-2012-1623 |
The Registration Codes module before 6.x-2.4 for Drupal does not
restrict access to the registration code list, which might allow
remote attackers to bypass intended registration restrictions.
|
| CVE-2012-1591 |
The image module in Drupal 7.x before 7.14 does not properly check
permissions when caching derivative image styles of private images,
which allows remote attackers to read private image styles.
|
| CVE-2012-1590 |
The forum list in Drupal 7.x before 7.14 does not properly check user
permissions for unpublished forum posts, which allows remote
authenticated users to obtain sensitive information such as the post
title via the forum overview page.
|
| CVE-2012-1589 |
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13
allows remote attackers to redirect users to arbitrary web sites and
conduct phishing attacks via crafted parameters in a destination URL.
|
| CVE-2012-1588 |
Algorithmic complexity vulnerability in the _filter_url function in
the text filtering system (modules/filter/filter.module) in Drupal 7.x
before 7.14 allows remote authenticated users with certain roles to
cause a denial of service (CPU consumption) via a long email address.
|
| CVE-2012-1561 |
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x
before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to the "checkbox and radio button
functionalities."
|
| CVE-2012-1060 |
Multiple cross-site scripting (XSS) vulnerabilities in
revisioning_theme.inc in the Taxonomy module in the Revisioning module
6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote
authenticated users with certain privileges to inject arbitrary web
script or HTML via the (1) tags or (2) term parameters.
|
| CVE-2012-1057 |
Cross-site request forgery (CSRF) vulnerability in the clickthrough
tracking functionality in the Forward module 6.x-1.x before 6.x-1.21
and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to
hijack the authentication of administrators for requests that increase
node rankings via the tracking code, possibly related to improper
"flood control."
|
| CVE-2012-1056 |
The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3
for Drupal does not properly enforce permissions for (1) Recent
forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows
remote attackers to obtain node titles via unspecified vectors.
|
| CVE-2012-0914 |
Cross-site scripting (XSS) vulnerability in
display_renderers/panels_renderer_editor.class.php in the admin view
in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before
7.x-3.0 for Drupal allows remote authenticated users with certain
privileges to inject arbitrary web script or HTML via the Region
title.
|
| CVE-2012-0827 |
The File module in Drupal 7.x before 7.11, when using unspecified
field access modules, allows remote authenticated users to read
arbitrary private files that are associated with restricted fields via
unspecified vectors.
|
| CVE-2012-0826 |
Cross-site request forgery (CSRF) vulnerability in the Aggregator
module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote
attackers to hijack the authentication of unspecified victims for
requests that update feeds and possibly cause a denial of service
(loss of updates due to rate limit) via unspecified vectors.
|
| CVE-2012-0825 |
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that
Attribute Exchange (AX) information is signed, which allows remote
attackers to modify potentially sensitive AX information without
detection via a man-in-the-middle (MITM) attack.
|
| CVE-2011-5189 |
Cross-site scripting (XSS) vulnerability in the Webform Validation
module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal
allows remote authenticated users with permissions to "update Webform
nodes" to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-5188 |
Cross-site scripting (XSS) vulnerability in the Support Timer module
6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users
with the "track time spent" permission to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2011-5187 |
Cross-site scripting (XSS) vulnerability in the Support Ticketing
System module 6.x-1.x before 6.x-1.7 for Drupal allows remote
authenticated users with the "administer support projects" permission
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-5030 |
Cross-site scripting (XSS) vulnerability in the Meta tags quick module
7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users
with certain permissions to inject arbitrary web script or HTML via
unspecified vectors, probably related to "names of entity bundles."
|
| CVE-2011-4560 |
Cross-site scripting (XSS) vulnerability in the Petition Node module
6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via unspecified vectors related to
signing a petition.
|
| CVE-2011-4113 |
SQL injection vulnerability in the Views module before 6.x-2.13 for
Drupal allows remote attackers to execute arbitrary SQL commands via
vectors related to "filters/arguments on certain types of views with
specific configurations of arguments."
|
| CVE-2011-3730 |
Drupal 7.0 allows remote attackers to obtain sensitive information via
a direct request to a .php file, which reveals the installation path
in an error message, as demonstrated by
modules/simpletest/tests/upgrade/drupal-6.upload.database.php and
certain other files.
|
| CVE-2011-2687 |
Drupal 7.x before 7.3 allows remote attackers to bypass intended
node_access restrictions via vectors related to a listing that shows
nodes but lacks a JOIN clause for the node table.
|
| CVE-2011-1664 |
Cross-site request forgery (CSRF) vulnerability in the Translation
Management module 6.x before 6.x-1.21 for Drupal allows remote
attackers to hijack the authentication of unspecified victims via
unknown vectors.
|
| CVE-2011-1663 |
SQL injection vulnerability in the Translation Management module 6.x
before 6.x-1.21 for Drupal allows remote attackers to execute
arbitrary SQL commands via unspecified vectors.
|
| CVE-2011-1662 |
Cross-site scripting (XSS) vulnerability in Translation Management
module 6.x before 6.x-1.21 for Drupal allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-1661 |
The Node Quick Find module 6.x-1.1 for Drupal does not use
db_rewrite_sql when presenting node titles, which allows remote
attackers to bypass intended access restrictions and read potentially
sensitive node titles via the autocomplete feature.
|
| CVE-2011-1066 |
Cross-site scripting (XSS) vulnerability in the Messaging module
6.x-2.x before 6.x-2.4 and 6.x-4.x before 6.x-4.0-beta8 for Drupal
allows remote attackers with administer messaging permissions to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2011-0899 |
The AES encryption module 7.x-1.4 for Drupal leaves certain debugging
code enabled in release, which records the plaintext password of the
last logged-in user and allows remote attackers to gain privileges as
that user.
|
| CVE-2011-0771 |
The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not
validate the file for a profile image, which allows remote
authenticated users to conduct cross-site scripting (XSS) attacks and
possibly execute arbitrary PHP code by causing a crafted avatar to be
downloaded from an external login provider site.
|
| CVE-2010-5277 |
Unspecified vulnerability in the Views Bulk Operations module 6 before
6.x-1.10 for Drupal allows remote authenticated users with user
management permissions to bypass intended access restrictions and
delete anonymous users (user 0) via unspecified vectors.
|
| CVE-2010-5276 |
The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for
Drupal does not properly handle the $user object in memcache_admin,
which might "lead to a role change not being recognized until the user
logs in again."
|
| CVE-2010-5275 |
Cross-site scripting (XSS) vulnerability in memcache_admin in the
Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2010-4813 |
Cross-site scripting (XSS) vulnerability in the Category Tokens module
6.x before 6.x-1.1 for Drupal allows remote authenticated users with
administer taxonomy permissions to inject arbitrary web script or HTML
by editing or creating vocabulary names, which are not properly
handled in token help.
|
| CVE-2010-4775 |
The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5
for Drupal does not properly implement node access logic, which allows
remote attackers to discover restricted node titles and relationships.
|
| CVE-2010-4521 |
Cross-site scripting (XSS) vulnerability in the Views module 6.x
before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary
web script or HTML via a page path.
|
| CVE-2010-4520 |
Multiple cross-site scripting (XSS) vulnerabilities in the Views
module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject
arbitrary web script or HTML via (1) a URL or (2) an aggregator feed
title.
|
| CVE-2010-4519 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x
before 6.x-2.11 for Drupal allow remote attackers to hijack the
authentication of administrators for requests that (1) enable all
Views or (2) disable all Views.
|
| CVE-2010-3686 |
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x
before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not
ensuring that fields are signed, which allows remote attackers to
bypass authentication by leveraging an assertion from an OpenID
provider.
|
| CVE-2010-3685 |
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x
before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not
checking for reuse of openid.response_nonce values, which allows
remote attackers to bypass authentication by leveraging an assertion
from an OpenID provider.
|
| CVE-2010-3423 |
SQL injection vulnerability in the Yr Weatherdata module for Drupal
6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL
commands via the sorting method.
|
| CVE-2010-3094 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x
before 6.18 allow remote authenticated users with certain privileges
to inject arbitrary web script or HTML via (1) an action description,
(2) an action message, (3) a node, or (4) a taxonomy term, related to
the actions feature and the trigger module.
|
| CVE-2010-3093 |
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18
allows remote authenticated users with certain privileges to bypass
intended access restrictions and reinstate removed comments via a
crafted URL, related to an "unpublishing bypass" issue.
|
| CVE-2010-3092 |
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does
not properly support case-insensitive filename handling in a database
configuration, which allows remote authenticated users to bypass the
intended restrictions on downloading a file by uploading a different
file with a similar name.
|
| CVE-2010-3091 |
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x
before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not
verifying the openid.return_to value, which allows remote attackers to
bypass authentication by leveraging an assertion from an OpenID
provider.
|
| CVE-2010-3022 |
Cross-site scripting (XSS) vulnerability in the Performance logging
module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21
for Drupal allows remote authenticated users, with add url aliases and
report access permissions, to inject arbitrary web script or HTML via
crafted node paths in a URL.
|
| CVE-2010-2724 |
Cross-site scripting (XSS) vulnerability in the Hierarchical Select
module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows
remote authenticated users, with administer taxonomy permissions, to
inject arbitrary web script or HTML via unspecified vectors in the
hierarchical_select form.
|
| CVE-2010-2353 |
The Node Reference module in Content Construction Kit (CCK) module 6.x
before 6.x-2.7 for Drupal does not perform access checks for the
source field in the backend URL for the autocomplete widget, which
allows remote attackers to discover titles and IDs of controlled
nodes.
|
| CVE-2010-2352 |
The Node Reference module in Content Construction Kit (CCK) module 5.x
before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform
access checks before displaying referenced nodes, which allows remote
attackers to read controlled nodes.
|
| CVE-2010-2158 |
Multiple cross-site scripting (XSS) vulnerabilities in the Storm
module 5.x and 6.x before 6.x-1.33 for Drupal allow remote
authenticated users, with certain module privileges, to inject
arbitrary web script or HTML via the (1) fullname, (2) phone, or (3)
im parameter in a stormperson action to index.php. NOTE: the
provenance of this information is unknown; the details are obtained
solely from third party information.
|
| CVE-2010-2125 |
Multiple cross-site scripting (XSS) vulnerabilities in the Rotor
Banner module 5.x before 5.x-1.8 and 6.x before 6.x-2.5 for Drupal
allow remote authenticated users, with "create rotor item" or "edit
any rotor item" privileges, to inject arbitrary web script or HTML via
the (1) srs, (2) title, or (3) alt image attribute.
|
| CVE-2010-2123 |
Multiple cross-site scripting (XSS) vulnerabilities in the Storm
module 5.x and 6.x before 6.x-1.33 for Drupal allow remote
authenticated users, with certain module privileges, to inject
arbitrary web script or HTML via the (1) fullname, (2) address, (3)
city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in
a stormorganization action to index.php; the (7) name parameter in a
stormperson action to index.php; the (8) stepno (aka Step no.) or (9)
title parameter in a stormtask action to index.php; the (10) title
(aka Project) parameter in a stormticket action to index.php; or (11)
unspecified parameters in a stormproject action to index.php. NOTE:
some of these details are obtained from third party information.
|
| CVE-2010-2048 |
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat
module 6.x before 6.x-4.9 for Drupal allow remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-2030 |
Cross-site scripting (XSS) vulnerability in the External Link Page
module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows
remote attackers to inject arbitrary web script or HTML via vectors
related to the administration and redirect pages.
|
| CVE-2010-2021 |
Open redirect vulnerability in the Global Redirect module 6.x-1.x
before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean
to clean is enabled, allows remote attackers to redirect users to
arbitrary web sites and conduct phishing attacks via a URL in the q
parameter.
|
| CVE-2010-2010 |
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool
Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote
attackers to inject arbitrary web script or HTML via a node title.
|
| CVE-2010-2002 |
Cross-site scripting (XSS) vulnerability in the Wordfilter module 5.x
before 5.x-1.1 and 6.x before 6.x-1.1 for Drupal allows remote
authenticated users, with "administer words filtered" privileges, to
inject arbitrary web script or HTML via the word list.
|
| CVE-2010-2001 |
Cross-site scripting (XSS) vulnerability in the CiviRegister module
before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary
web script or HTML via the URI.
|
| CVE-2010-2000 |
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio)
module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows
remote authenticated users, with "administer biblio" privileges, to
inject arbitrary web script or HTML via unspecified vectors, a
different vulnerability than CVE-2010-1358.
|
| CVE-2010-1998 |
Cross-site scripting (XSS) vulnerability in the CCK TableField module
6.x before 6.x-1.2 for Drupal allows remote authenticated users, with
certain node creation or editing privileges, to inject arbitrary web
script or HTML via table headers.
|
| CVE-2010-1984 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb
module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows
remote authenticated users, with administer taxonomy permissions, to
inject arbitrary web script or HTML via the taxonomy term name in a
Breadcrumb display.
|
| CVE-2010-1976 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb
module 6.x before 6.x-1.1 for Drupal allows remote authenticated
users, with administer taxonomy permissions, to inject arbitrary web
script or HTML via the node title in a Breadcrumb display.
|
| CVE-2010-1958 |
Cross-site scripting (XSS) vulnerability in the FileField module 5.x
before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote
authenticated users, with create or edit permissions and 'Path to
File' or 'URL to File' display enabled, to inject arbitrary web script
or HTML via the file name (filepath parameter).
|
| CVE-2010-1584 |
Cross-site scripting (XSS) vulnerability in the Context module before
6.x-2.0-rc4 for Drupal allows remote authenticated users, with
Administer Blocks privileges, to inject arbitrary web script or HTML
via a block description.
|
| CVE-2010-1548 |
The auto-complete functionality in the Chaos Tool Suite (aka CTools)
module 6.x before 6.x-1.4 for Drupal does not follow access
restrictions, which allows remote authenticated users, with "access
content" privileges, to read the title of an unpublished node via a
q=ctools/autocomplete/node/ value accompanied by the first character
of the node's title.
|
| CVE-2010-1547 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal
allow remote attackers to hijack the authentication of administrators
for requests that (1) enable a page via a
q=admin/build/pages/nojs/enable/ value or (2) disable a page via a
q=admin/build/pages/nojs/disable/ value.
|
| CVE-2010-1546 |
Multiple eval injection vulnerabilities in the import functionality in
the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal
allow remote authenticated users, with "administer page manager"
privileges, to execute arbitrary PHP code via input to a text area,
related to (1) the page_manager_page_import_subtask_validate function
in page_manager/plugins/tasks/page.admin.inc and (2) the
page_manager_handler_import_validate function in
page_manager/page_manager.admin.inc.
|
| CVE-2010-1543 |
Cross-site scripting (XSS) vulnerability in the eTracker module before
6.x-1.2 for Drupal allows remote attackers to inject arbitrary web
script or HTML by appending a crafted string to an arbitrary URL
associated with the Drupal site.
|
| CVE-2010-1539 |
Cross-site scripting (XSS) vulnerability in the Workflow module
5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when
used with the Token module, might allow remote authenticated users to
inject arbitrary web script or HTML via a certain Comment field.
|
| CVE-2010-1536 |
Cross-site scripting (XSS) vulnerability in the AddThis Button module
5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote
authenticated users, with administer addthis privileges, to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1530 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Internationalization module 6.x before 6.x-1.4 for Drupal allow remote
authenticated users, with translate interface or administer blocks
privileges, to inject arbitrary web script or HTML via (1) strings
used in block translation or (2) the untranslated input.
|
| CVE-2010-1362 |
Cross-site scripting (XSS) vulnerability in the Own Term module
6.x-1.0 for Drupal allows remote authenticated users, with "create
additional terms" privileges, to inject arbitrary web script or HTML
via the term description field in a term listing page.
|
| CVE-2010-1358 |
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio)
module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows
remote authenticated users, with "administer biblio" privileges, to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1303 |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy
Filter module 6.x before 6.x-1.1 for Drupal allow remote authenticated
users, with administer taxonomy permissions or create node permissions
when free tagging is enabled, to inject arbitrary web script or HTML
via vocabulary (1) names, (2) terms, and (3) filter menus.
|
| CVE-2010-1108 |
Cross-site scripting (XSS) vulnerability in the Control Panel module
5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote
authenticated users, with "administer blocks" privileges, to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2010-1107 |
Cross-site scripting (XSS) vulnerability in the Recent Comments module
5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML via a
"custom block title interface."
|
| CVE-2010-1074 |
Cross-site scripting (XSS) vulnerability in the Currency Exchange
module before 6.x-1.2 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors, related to
watchdog logging.
|
| CVE-2010-0752 |
The week_post_page function in the Weekly Archive by Node Type module
6.x before 6.x-2.7 for Drupal does not properly implement node access
restrictions when constructing SQL queries, which allows remote
attackers to read restricted node listings via unspecified vectors.
|
| CVE-2010-0697 |
Cross-site scripting (XSS) vulnerability in the iTweak Upload module
6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows
remote authenticated users, with create content and upload file
permissions, to inject arbitrary web script or HTML via the file name
of an uploaded file.
|
| CVE-2010-0370 |
Cross-site scripting (XSS) vulnerability in the Node Blocks module
5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal,
allows remote authenticated users, with permissions to create or edit
content and administer blocks, to inject arbitrary web script or HTML
via the edit-title parameter (aka block title).
|
| CVE-2009-5096 |
Cross-site scripting (XSS) vulnerability in the Flag Content module
5.x-2.x before 5.x-2.10 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the Reason parameter.
|
| CVE-2009-4990 |
Cross-site scripting (XSS) vulnerability in the Webform report module
5.x and 6.x for Drupal allows remote attackers to inject arbitrary web
script or HTML via a submission.
|
| CVE-2009-4829 |
Cross-site scripting (XSS) vulnerability in the Automated Logout
module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.3 for Drupal
allows remote authenticated users with administer autologout
privileges to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4773 |
Cross-site request forgery (CSRF) vulnerability in the
order-management functionality in the Ubercart module 5.x before
5.x-1.9 and 6.x before 6.x-2.1 for Drupal allows remote attackers to
hijack the authentication of unspecified victims via unknown vectors.
|
| CVE-2009-4772 |
Unspecified vulnerability in the PayPal Website Payments Standard
functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before
6.x-2.1 for Drupal, when a custom checkout completion message is
enabled, allows attackers to obtain sensitive information via unknown
vectors.
|
| CVE-2009-4771 |
The PayPal Website Payments Standard functionality in the Ubercart
module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal does not
properly validate orders, which allows remote attackers to trigger
unspecified "duplicate actions" via unknown vectors.
|
| CVE-2009-4602 |
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x
through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-4559 |
Cross-site scripting (XSS) vulnerability in the Submitted By module
6.x before 6.x-1.3 for Drupal allows remote authenticated users, with
"administer content types" privileges, to inject arbitrary web script
or HTML via an input string for "submitted by" text.
|
| CVE-2009-4558 |
The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before
2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and
6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly
enforce privilege requirements for unspecified pages, which allows
remote attackers to read the (1) title or (2) body of an arbitrary
node via unknown vectors.
|
| CVE-2009-4557 |
Cross-site scripting (XSS) vulnerability in the Image Assist module
5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before
6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15,
a module for Drupal, allows remote authenticated users, with
image-node creation privileges, to inject arbitrary web script or HTML
via a node title.
|
| CVE-2009-4534 |
Open redirect vulnerability in the FAQ Ask module 5.x and 6.x before
6.x-2.0, a module for Drupal, allows remote attackers to redirect
users to arbitrary web sites and conduct phishing attacks via
unspecified vectors.
|
| CVE-2009-4533 |
The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module
for Drupal, does not prevent caching of a page that contains token
placeholders for a default value, which allows remote attackers to
read session variables via unspecified vectors.
|
| CVE-2009-4532 |
Cross-site scripting (XSS) vulnerability in the Webform module 5.x
before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows
remote authenticated users, with webform creation privileges, to
inject arbitrary web script or HTML via a field label.
|
| CVE-2009-4528 |
The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for
Drupal allows remote authenticated group members to bypass intended
access restrictions, and create, modify, or read a vocabulary, via
unspecified vectors.
|
| CVE-2009-4527 |
The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before
6.x-3.2, a module for Drupal, does not properly remove statically
granted privileges after a logout or other session change, which
allows physically proximate attackers to gain privileges by using an
unattended web browser.
|
| CVE-2009-4526 |
The Send by e-mail sub-module in the Print (aka Printer, e-mail and
PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a
module for Drupal, does not properly enforce privilege requirements,
which allows remote attackers to read page titles by requesting a
"Send to friend" form.
|
| CVE-2009-4525 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before
6.x-1.9, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via crafted data in a list of links.
|
| CVE-2009-4524 |
Cross-site scripting (XSS) vulnerability in the RealName module
6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via a realname (aka real name) element.
|
| CVE-2009-4520 |
The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before
6.x-1.3, a module for Drupal, allows remote attackers to bypass
intended access restrictions and read comments by using the
autocomplete path.
|
| CVE-2009-4518 |
Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x
before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary
web script or HTML via an inserted node.
|
| CVE-2009-4517 |
Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module
5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote
attackers to hijack the authentication of arbitrary users for requests
that access unpublished content.
|
| CVE-2009-4516 |
Cross-site scripting (XSS) vulnerability in the FAQ Ask module 5.x and
6.x before 6.x-2.0, a module for Drupal, allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4515 |
The Storm module 6.x before 6.x-1.25 for Drupal does not enforce
privilege requirements for storminvoiceitem nodes, which allows remote
attackers to read node titles via unspecified vectors.
|
| CVE-2009-4514 |
Cross-site scripting (XSS) vulnerability in the OpenSocial
Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a module for
Drupal, allows remote authenticated users, with "create application"
privileges, to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4513 |
Multiple cross-site scripting (XSS) vulnerabilities in the Workflow
module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a module for Drupal,
allow remote authenticated users, with "administer workflow"
privileges, to inject arbitrary web script or HTML via the name of a
(1) workflow or (2) workflow state.
|
| CVE-2009-4429 |
Cross-site scripting (XSS) vulnerability in the Sections module 5.x
before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote
authenticated users with "administer sections" privileges to inject
arbitrary web script or HTML via a section name (aka the Name field).
|
| CVE-2009-4371 |
Cross-site scripting (XSS) vulnerability in the Locale module
(modules/locale/locale.module) in Drupal Core 6.14, and possibly other
versions including 6.15, allows remote authenticated users with
"administer languages" permissions to inject arbitrary web script or
HTML via the (1) Language name in English or (2) Native language name
fields in the Custom language form.
|
| CVE-2009-4370 |
Cross-site scripting (XSS) vulnerability in the Menu module
(modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows
remote authenticated users with permissions to create new menus to
inject arbitrary web script or HTML via a menu description, which is
not properly handled in the menu administration overview.
|
| CVE-2009-4369 |
Cross-site scripting (XSS) vulnerability in the Contact module
(modules/contact/contact.admin.inc or modules/contact/contact.module)
in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote
authenticated users with "administer site-wide contact form"
permissions to inject arbitrary web script or HTML via the contact
category name.
|
| CVE-2009-4296 |
SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and
earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers
to execute arbitrary SQL commands via unspecified vectors.
|
| CVE-2009-4207 |
Cross-site scripting (XSS) vulnerability in the Webform module 5.x
before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via a
submission.
|
| CVE-2009-4119 |
Cross-site scripting (XSS) vulnerability in Feed Element Mapper module
5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2.0-alpha before
6.x-2.0-alpha4 for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2009-4066 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My
Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6
before 6.x-1.1 for Drupal allow remote attackers to hijack the
authentication of arbitrary users via vectors related to (1)
subscribing or (2) unsubscribing to mailing lists.
|
| CVE-2009-4065 |
Cross-site scripting (XSS) vulnerability in the settings page in the
Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers
to inject arbitrary web script or HTML via the value field when
viewing overridden variables.
|
| CVE-2009-4064 |
Cross-site scripting (XSS) vulnerability in the Gallery Assist module
6.x before 6.x-1.7 for Drupal allows remote attackers to inject
arbitrary web script or HTML via node titles.
|
| CVE-2009-4063 |
Cross-site scripting (XSS) vulnerability in the Subgroups for Organic
Groups (OG) module 5.x before 5.x-4.0 and 5.x before 5.x-3.4 for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified node titles.
|
| CVE-2009-4062 |
Multiple cross-site scripting (XSS) vulnerabilities in the
Printfriendly module 6.x before 6.x-1.6 for Drupal allow remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-4061 |
Multiple cross-site scripting (XSS) vulnerabilities in the Agreement
module 6.x before 6.x-1.2 for Drupal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-4044 |
The Web Services module 6.x for Drupal does not perform the expected
access control, which allows remote attackers to make unspecified use
of an API via unknown vectors.
|
| CVE-2009-4043 |
Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x
before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote
attackers to inject arbitrary web script or HTML via a node title.
|
| CVE-2009-4042 |
Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x
before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary
web script or HTML via the URI.
|
| CVE-2009-3922 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the User
Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for
Drupal, allow remote attackers to hijack the authentication of
administrators for requests that (1) delete the editing protection of
a user or (2) delete a certain type of administrative-bypass rule.
|
| CVE-2009-3921 |
The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before
6.x-1.0-rc3, a module for Drupal, does not verify group-node
privileges in certain circumstances involving subqueue creation, which
allows remote authenticated users to discover arbitrary organic group
names by reading confirmation messages.
|
| CVE-2009-3920 |
An administration page in the NGP COO/CWP Integration (crmngp) module
6.x before 6.x-1.12 for Drupal does not perform the expected access
control, which allows remote attackers to read log information via
unspecified vectors.
|
| CVE-2009-3919 |
Cross-site scripting (XSS) vulnerability in the NGP COO/CWP
Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows
remote attackers to inject arbitrary web script or HTML via
unspecified "user-supplied information."
|
| CVE-2009-3918 |
Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x
before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via the node
title.
|
| CVE-2009-3917 |
Cross-site scripting (XSS) vulnerability in the S5 Presentation Player
module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to
inject arbitrary web script or HTML via an unspecified field that is
copied to the HTML HEAD element.
|
| CVE-2009-3916 |
Cross-site scripting (XSS) vulnerability in the Node Hierarchy module
5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via a child
node title.
|
| CVE-2009-3915 |
Cross-site scripting (XSS) vulnerability in the "Separate title and
URL" formatter in the Link module 5.x before 5.x-2.6 and 6.x before
6.x-2.7, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via the link title field.
|
| CVE-2009-3914 |
Cross-site scripting (XSS) vulnerability in the Temporary Invitation
module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject
arbitrary web script or HTML via the Name field in an invitation.
|
| CVE-2009-3786 |
Cross-site scripting (XSS) vulnerability in Organic Groups (OG)
Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for
Drupal, allows remote attackers to inject arbitrary web script or HTML
via the group title.
|
| CVE-2009-3785 |
Multiple cross-site request forgery (CSRF) vulnerabilities in
Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow
remote attackers to hijack the authentication of arbitrary users via
unknown vectors.
|
| CVE-2009-3784 |
Open redirect vulnerability in Simplenews Statistics 6.x before
6.x-2.0, a module for Drupal, allows remote attackers to redirect
users to arbitrary web sites and conduct phishing attacks via
unspecified vectors.
|
| CVE-2009-3783 |
Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x
before 6.x-2.0, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via unspecified vector.
|
| CVE-2009-3782 |
Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module
for Drupal, allows remote authenticated users with "View own
userpoints" permissions to read the userpoint data of arbitrary users
via unknown attack vectors.
|
| CVE-2009-3781 |
The filefield_file_download function in FileField 6.x-3.1, a module
for Drupal, does not properly check node-access permissions for Drupal
core private files, which allows remote attackers to access
unauthorized files via unspecified vectors.
|
| CVE-2009-3780 |
Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1
and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-3779 |
Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4
and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors,
related to the addition of the theme_vcard function to a theme and the
use of default content.
|
| CVE-2009-3778 |
SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2,
a module for Drupal, allows remote attackers to execute arbitrary SQL
commands via unspecified vectors.
|
| CVE-2009-3657 |
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module
for Drupal, allows remote attackers to hijack web sessions via
unspecified vectors.
|
| CVE-2009-3656 |
Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x
and 6.x, a module for Drupal, allows remote attackers to hijack the
authentication of arbitrary users via unknown vectors.
|
| CVE-2009-3654 |
Unspecified vulnerability in Boost before 6.x-1.03, a module for
Drupal, allows remote attackers to create new webroot directories via
unknown attack vectors.
|
| CVE-2009-3653 |
Cross-site scripting (XSS) vulnerability in the additional links
interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote
authenticated users, with "administer site configuration" permission,
to inject arbitrary web script or HTML via unspecified vectors,
related to link path output.
|
| CVE-2009-3652 |
Cross-site scripting (XSS) vulnerability in Organic Groups (OG)
5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before
6.x-1.4, a module for Drupal, allows remote authenticated users, with
create or edit group nodes permissions, to inject arbitrary web script
or HTML via the User-Agent HTTP header, a different issue than
CVE-2008-3095.
|
| CVE-2009-3651 |
Cross-site scripting (XSS) vulnerability in the "Monitor browsers'
feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via the
User-Agent HTTP header.
|
| CVE-2009-3650 |
Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier
and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-3648 |
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a
module for Drupal, allows remote authenticated users, with 'administer
content types' permissions, to inject arbitrary web script or HTML via
unspecified vectors when displaying content type names.
|
| CVE-2009-3568 |
Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for
Drupal, does not properly enforce permissions when a link is added to
the RSS feed, which allows remote attackers to obtain the node title
and possibly other sensitive content by reading the feed.
|
| CVE-2009-3488 |
Cross-site scripting (XSS) vulnerability in the Bibliography (aka
Biblio) module 6.x-1.6 for Drupal allows remote authenticated users,
with certain content-creation privileges, to inject arbitrary web
script or HTML via the Title field, probably a different vulnerability
than CVE-2009-3479.
|
| CVE-2009-3479 |
Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x
before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows
remote attackers, with "create content displayed by the Bibliography
module" permissions, to inject arbitrary web script or HTML via a
title.
|
| CVE-2009-3442 |
The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does
not properly follow permissions during assignment of node meta tags,
which allows remote attackers to obtain sensitive information via
unspecified vectors.
|
| CVE-2009-3437 |
Cross-site scripting (XSS) vulnerability in the live preview feature
in the Markdown Preview module 6.x for Drupal allows remote attackers
to inject arbitrary web script or HTML via "Markdown input."
|
| CVE-2009-3435 |
Cross-site scripting (XSS) vulnerability in the variable editor in the
Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for
Drupal, allows remote attackers to inject arbitrary web script or HTML
via a variable name.
|
| CVE-2009-3363 |
Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x
before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via input to
the "plain textarea editor."
|
| CVE-2009-3354 |
Multiple unspecified vulnerabilities in the Rest API module for Drupal
have unknown impact and attack vectors.
|
| CVE-2009-3353 |
Multiple unspecified vulnerabilities in the Node2Node module for
Drupal have unknown impact and attack vectors.
|
| CVE-2009-3352 |
Multiple unspecified vulnerabilities in the quota_by_role (Quota by
role) module for Drupal have unknown impact and attack vectors.
|
| CVE-2009-3351 |
Multiple unspecified vulnerabilities in the Node Browser module for
Drupal have unknown impact and attack vectors.
|
| CVE-2009-3350 |
Multiple unspecified vulnerabilities in the Subdomain Manager module
for Drupal have unknown impact and attack vectors.
|
| CVE-2009-3210 |
Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka
Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x
before 6.x-1.8, a module for Drupal, allow remote authenticated users
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2009-3207 |
The ImageCache module 5.x before 5.x-2.5 and 6.x before
6.x-2.0-beta10, a module for Drupal, when the private file system is
used, does not properly perform access control for derivative images,
which allows remote attackers to view arbitrary images via a request
that specifies an image's filename.
|
| CVE-2009-3206 |
Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache
module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for
Drupal, allow remote authenticated users, with "administer imagecache"
permissions, to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-3157 |
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x
before 6.x-2.2 for Drupal allows remote authenticated users, with
"create new content types" privileges, to inject arbitrary web script
or HTML via the title of a content type.
|
| CVE-2009-3156 |
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module
in the Date module 6.x before 6.x-2.3 for Drupal allows remote
authenticated users, with "use date tools" or "administer content
types" privileges, to inject arbitrary web script or HTML via a
"Content type label" field.
|
| CVE-2009-3122 |
The Ajax Table module 5.x for Drupal does not perform access control,
which allows remote attackers to delete arbitrary users and nodes via
unspecified vectors.
|
| CVE-2009-3121 |
Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x
for Drupal allows remote attackers to inject arbitrary web script or
HTML via unspecified vectors.
|
| CVE-2009-2610 |
Cross-site scripting (XSS) vulnerability in the Links Related module
in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a
module for Drupal, allows remote authenticated users to inject
arbitrary web script or HTML via the title field.
|
| CVE-2009-2572 |
Cross-site request forgery (CSRF) vulnerability in the Fivestar module
5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for
Drupal, allows remote attackers to hijack the authentication of
arbitrary users for requests that cast votes.
|
| CVE-2009-2374 |
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize
failed login attempts for pages that contain a sortable table, which
includes the username and password in links that can be read from (1)
the HTTP referer header of external web sites that are visited from
those links or (2) when page caching is enabled, the Drupal page
cache.
|
| CVE-2009-2373 |
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal
6.x before 6.13 allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2009-2372 |
Drupal 6.x before 6.13 does not prevent users from modifying user
signatures after the associated comment format has been changed to an
administrator-controlled input format, which allows remote
authenticated users to inject arbitrary web script, HTML, and possibly
PHP code via a crafted user signature.
|
| CVE-2009-2371 |
Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not
prevent users from modifying user signatures after the associated
comment format has been changed to an administrator-controlled input
format, which allows remote authenticated users to inject arbitrary
web script, HTML, and possibly PHP code via a crafted user signature.
|
| CVE-2009-2370 |
Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before
5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2009-2291 |
Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a
module for Drupal, when "Allow users to login using their e-mail
address" is enabled, allows remote blocked users to bypass intended
access restrictions via unspecified vectors.
|
| CVE-2009-2237 |
Unspecified vulnerability in Views Bulk Operations 5.x-1.x before
5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote
attackers to bypass intended access restrictions and modify "nodes or
classes of nodes" via unknown vectors, probably related to registered
procedures (aka actions).
|
| CVE-2009-2083 |
Cross-site scripting (XSS) vulnerability in the term data detail page
in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows
remote authenticated users, with administer taxonomy privileges or the
ability to use free tagging to add taxonomy terms, to inject arbitrary
web script or HTML via "Parent and related terms."
|
| CVE-2009-2079 |
Cross-site scripting (XSS) vulnerability in the administrative page
interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before
6.x-1.1, a module for Drupal, allows remote authenticated users, with
administer taxonomy privileges or the ability to use free tagging to
add taxonomy terms, to inject arbitrary web script or HTML via (1)
vocabulary names, (2) synonyms, and (3) term names.
|
| CVE-2009-2078 |
Multiple cross-site scripting (XSS) vulnerabilities in Booktree 5.x
before 5.x-7.3 and 6.x before 6.x-1.1, a module for Drupal, allow
remote attackers to inject arbitrary web script or HTML via the (1)
node title and (2) node body in a tree root page.
|
| CVE-2009-2077 |
Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote
authenticated users to bypass access restrictions and (1) read
unpublished content from anonymous users when a view is already
configured to display the content, and (2) read private content in
generated queries.
|
| CVE-2009-2076 |
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6,
a module for Drupal, allows remote authenticated users to inject
arbitrary web script or HTML via (1) exposed filters in the Views UI
administrative interface and in the (2) view name parameter in the
define custom views feature. NOTE: vector 2 is only exploitable by
users with administer views permissions.
|
| CVE-2009-2075 |
Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for
Drupal, does not properly restrict access when displaying node titles,
which has unknown impact and attack vectors.
|
| CVE-2009-2074 |
Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before
5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, allows remote
authenticated users with administer taxonomy permissions to inject
arbitrary web script or HTML via vocabulary names.
|
| CVE-2009-2035 |
Unspecified vulnerability in Services 6.x before 6.x-0.14, a module
for Drupal, when key-based access is enabled, allows remote attackers
to read or add keys and access unauthorized services via unspecified
vectors.
|
| CVE-2009-1942 |
Cross-site scripting (XSS) vulnerability in the Quiz module 5.x,
6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for
Drupal, allows remote authenticated users, with create quizzes or quiz
questions access, to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2009-1844 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x
before 5.18 and 6.x before 6.12 allow (1) remote authenticated users
to inject arbitrary web script or HTML via crafted UTF-8 byte
sequences that are treated as UTF-7 by Internet Explorer 6 and 7,
which are not properly handled in the "HTML exports of books" feature;
and (2) allow remote authenticated users with administer taxonomy
permissions to inject arbitrary web script or HTML via the help text
of an arbitrary vocabulary. NOTE: vector 1 exists because of an
incomplete fix for CVE-2009-1575.
|
| CVE-2009-1823 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 5.x before 5.x-4.7 and 6.x before
6.x-1.7, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML by modifying a document head, before the
Content-Type META element, to contain crafted UTF-8 byte sequences
that are treated as UTF-7 by Internet Explorer 6 and 7, a related
issue to CVE-2009-1575.
|
| CVE-2009-1738 |
Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before
6.x-1.1, a module for Drupal, allows remote authenticated users with
administrator feed permissions to inject arbitrary web script or HTML
via unspecified vectors in "aggregator items."
|
| CVE-2009-1576 |
Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before
6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote
attackers to obtain sensitive information by tricking victims into
visiting the front page of the site with a crafted URL and causing
form data to be sent to an attacker-controlled site, possibly related
to multiple / (slash) characters that are not properly handled by
includes/bootstrap.inc, as demonstrated using the search box. NOTE:
this vulnerability can be leveraged to conduct cross-site request
forgery (CSRF) attacks.
|
| CVE-2009-1575 |
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and
6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote
attackers to inject arbitrary web script or HTML via crafted UTF-8
byte sequences before the Content-Type meta tag, which are treated as
UTF-7 by Internet Explorer 6 and 7.
|
| CVE-2009-1507 |
The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x
before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK
user reference as a reference to the anonymous user, which might allow
remote attackers to bypass intended access restrictions to read or
modify a node.
|
| CVE-2009-1505 |
SQL injection vulnerability in the News Page module 5.x before 5.x-1.2
for Drupal allows remote authenticated users, with News Page nodes
create and edit privileges, to execute arbitrary SQL commands via the
Include Words (aka keywords) field.
|
| CVE-2009-1501 |
Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x
before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for
Drupal, allows remote attackers to inject arbitrary web script or HTML
via EXIF tags in an image.
|
| CVE-2009-1344 |
Cross-site scripting (XSS) vulnerability in the Localization client
module 5.x before 5.x-1.2 and 6.x before 6.x-1.7, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via
input to the translation functionality.
|
| CVE-2009-1343 |
Cross-site scripting (XSS) vulnerability in the Print (aka Printer,
e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before
6.x-1.5, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via content titles.
|
| CVE-2009-1342 |
Cross-site scripting (XSS) vulnerability in the CCK comment reference
module 6.x before 6.x-1.2, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via certain comment
titles associated with a node edit form.
|
| CVE-2009-1249 |
Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x
before 5.x-1.1, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via the content title in
admin/content/node-type/nodetype/map.
|
| CVE-2009-1069 |
Multiple cross-site scripting (XSS) vulnerabilities in the node edit
form feature in Drupal Content Construction Kit (CCK) 6.x before
6.x-2.2, a module for Drupal, allow remote attackers to inject
arbitrary web script or HTML via the (1) titles of candidate
referenced nodes in the Node reference sub-module and the (2) names of
candidate referenced users in the User reference sub-module.
|
| CVE-2009-1047 |
Cross-site scripting (XSS) vulnerability in the Send by e-mail module
in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4
and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers
to inject arbitrary web script or HTML via vectors involving outbound
HTML e-mail.
|
| CVE-2009-1037 |
Unspecified vulnerability in the Send by e-mail module in the
"Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x
before 6.x-1.4, a module for Drupal, allows remote attackers to send
unlimited spam messages via unknown vectors related to the flood
control API.
|
| CVE-2009-1036 |
Cross-site request forgery (CSRF) vulnerability in the Plus 1 module
before 6.x-2.6, a module for Drupal, allows remote attackers to cast
votes for content via unspecified aspects of the URI.
|
| CVE-2009-1035 |
Cross-site scripting (XSS) vulnerability in the Tasklist module
5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for
Drupal, allows remote authenticated users to inject arbitrary web
script or HTML via Cascading Style Sheets (CSS).
|
| CVE-2009-1034 |
SQL injection vulnerability in the Tasklist module 5.x-1.x before
5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows
remote attackers to execute arbitrary SQL commands via values in the
URI.
|
| CVE-2009-0818 |
Cross-site scripting (XSS) vulnerability in the
taxonomy_theme_admin_table_builder function (taxonomy_theme_admin.inc)
in Taxonomy Theme module before 5.x-1.2, a module for Drupal, allows
remote authenticated users with the "administer taxonomy" permission,
or the ability to create pages when tagging is enabled, to inject
arbitrary web script or HTML via the Vocabulary name (name parameter)
to index.php. NOTE: some of these details are obtained from third
party information.
|
| CVE-2009-0817 |
Cross-site scripting (XSS) vulnerability in the Protected Node module
5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows
remote authenticated users with "administer site configuration"
permissions to inject arbitrary web script or HTML via the Password
page info field, which is not properly handled by the
protected_node_enterpassword function in protected_node.module.
|
| CVE-2009-0603 |
Cross-site scripting (XSS) vulnerability in index.php in the Link
module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with
"administer content types" privileges, to inject arbitrary web script
or HTML via the description parameter (aka the Help field). NOTE: some
of these details are obtained from third party information.
|
| CVE-2009-0575 |
Cross-site scripting (XSS) vulnerability in the
theme_views_bulk_operations_confirmation function in
views_bulk_operations.module in Views Bulk Operations 5.x before
5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors related to node titles. NOTE: some of these details are
obtained from third party information.
|
| CVE-2009-0382 |
Unspecified vulnerability in Internationalization (i18n) Translation
5.x before 5.x-2.5, a module for Drupal, allows remote attackers with
"translate node" permissions to bypass intended access restrictions
and read unpublished nodes via unspecified vectors.
|
| CVE-2008-7151 |
Cross-site request forgery (CSRF) vulnerability in Live 5.x before
5.x-0.1, a module for Drupal, allows remote attackers to hijack the
authentication of unspecified privileged users for requests that can
be leveraged to execute arbitrary PHP code.
|
| CVE-2008-7150 |
Cross-site scripting (XSS) vulnerability in Refine by Taxonomy 5.x
before 5.x-0.1, a module for Drupal, allows remote attackers to inject
arbitrary web script or HTML via a taxonomy term, which is not
properly handled by refine_by_taxo when displaying tags.
|
| CVE-2008-6972 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content
Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated
users with "administer content" permissions to inject arbitrary web
script or HTML via the (1) "field label," (2) "help text," or (3)
"allowed values" settings.
|
| CVE-2008-6910 |
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for
Drupal, does not use timeouts for signed requests, which allows remote
attackers to impersonate other users and gain privileges via a replay
attack that sends the same request.
|
| CVE-2008-6909 |
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for
Drupal, does not sign all required data in requests, which has
unspecified impact, probably related to man-in-the-middle attacks that
modify critical data and allow remote attackers to impersonate other
users and gain privileges.
|
| CVE-2008-6908 |
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for
Drupal, uses an insecure hash when signing requests, which allows
remote attackers to impersonate other users and gain privileges.
|
| CVE-2008-6836 |
Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before
5x.-1.2, a module for Drupal, allows remote attackers to hijack the
authentication of unspecified victims to delete OpenID identities via
unknown vectors.
|
| CVE-2008-6835 |
Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2,
a module for Drupal, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-6533 |
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related
content when an input format is deleted, which prevents the content
from being properly filtered and allows remote attackers to conduct
cross-site scripting (XSS) attacks via unspecified vectors.
|
| CVE-2008-6532 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow
remote attackers to perform unauthorized actions as the superuser via
unspecified vectors, as demonstrated by causing the superuser to
"execute old updates" that modify the database.
|
| CVE-2008-6413 |
Cross-site scripting (XSS) vulnerability in the Answers module
5.x-1.x-dev and possibly other 5.x versions, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via a
Simple Answer to a question.
|
| CVE-2008-6384 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Comment
Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers
to hijack the authentication of administrators.
|
| CVE-2008-6383 |
SQL injection vulnerability in SpeedTech Organization and Resource
Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module
for Drupal, allows remote authenticated users with storm project
access to execute arbitrary SQL commands via unspecified vectors.
|
| CVE-2008-6276 |
Multiple SQL injection vulnerabilities in the User Karma module 5.x
before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal,
allow remote authenticated administrators to execute arbitrary SQL
commands via (1) a content type or (2) a voting API value.
|
| CVE-2008-6275 |
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x
before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal,
allows remote attackers to inject arbitrary web script or HTML via
unspecified messages.
|
| CVE-2008-6229 |
Cross-site scripting (XSS) vulnerability in the administrative
interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10
and 6.x before 6.x-2.0, a module for Drupal, allows remote
authenticated users with "administer content" permissions to inject
arbitrary web script or HTML via (1) field labels and (2) content-type
names.
|
| CVE-2008-6171 |
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6,
when the server is configured for "IP-based virtual hosts," allows
remote attackers to include and execute arbitrary files via the HTTP
Host header.
|
| CVE-2008-6170 |
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and
6.x before 6.6 allows remote authenticated users with create book
content or edit node book hierarchy permissions to inject arbitrary
web script or HTML via the book page title.
|
| CVE-2008-6169 |
Cross-site request forgery (CSRF) vulnerability in the Localization
client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization
server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules
for Drupal, allows remote attackers to perform unauthorized actions as
administrators via unspecified vectors related to the "local
translation submission interface."
|
| CVE-2008-6160 |
Semantically-Interconnected Online Communities (SIOC) 5.x before
5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly
implement menu and database APIs, which allows remote attackers to
obtain usernames and read hashed emails and comments via unspecified
vectors.
|
| CVE-2008-6137 |
EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to
bypass access restrictions via unknown vectors.
|
| CVE-2008-6136 |
Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for
Drupal, allows remote attackers to gain privileges as another user or
an administrator via unknown attack vectors.
|
| CVE-2008-6135 |
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a
module for Drupal, allows remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-6134 |
SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for
Drupal, allows remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2008-6020 |
SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for
Drupal allows remote attackers to execute arbitrary SQL commands via
unspecified vectors related to "an exposed filter on CCK text fields."
|
| CVE-2008-5999 |
Cross-site scripting (XSS) vulnerability in the Ajax Checklist module
5.x before 5.x-1.1 for Drupal allows remote authenticated users, with
create and edit permissions for posts, to inject arbitrary web script
or HTML via unspecified vectors involving the ajax_checklist filter.
|
| CVE-2008-5998 |
Multiple SQL injection vulnerabilities in the ajax_checklist_save
function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal
allow remote authenticated users, with "update ajax checklists"
permissions, to execute arbitrary SQL commands via a save operation,
related to the (1) nid, (2) qid, and (3) state parameters.
|
| CVE-2008-5996 |
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x
before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal,
allows remote authenticated users, with "administer taxonomy"
permissions, to inject arbitrary web script or HTML via a Newsletter
category field.
|
| CVE-2008-4793 |
The node module API in Drupal 5.x before 5.11 allows remote attackers
to bypass node validation and have unspecified other impact via
unknown vectors related to contributed modules.
|
| CVE-2008-4792 |
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5
does not properly validate unspecified content fields of an internal
Drupal form, which allows remote authenticated users to bypass
intended access restrictions via modified field values.
|
| CVE-2008-4791 |
The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might
allow remote authenticated users to bypass intended login access rules
and successfully login via unknown vectors.
|
| CVE-2008-4790 |
The core upload module in Drupal 5.x before 5.11 allows remote
authenticated users to bypass intended access restrictions and read
"files attached to content" via unknown vectors.
|
| CVE-2008-4789 |
The validation functionality in the core upload module in Drupal 6.x
before 6.5 allows remote authenticated users to bypass intended access
restrictions and "attach files to content," related to a "logic
error."
|
| CVE-2008-4710 |
Cross-site scripting (XSS) vulnerability in the stock quotes page in
Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers
to inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-4633 |
SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x
before 6.x-1.0, a module for Drupal, when "Allow user to vote again"
is enabled, allows remote authenticated users to execute arbitrary SQL
commands via unspecified vectors related to a "previously cast vote."
|
| CVE-2008-4598 |
Unspecified vulnerability in Shindig-Integrator 5.x, a module for
Drupal, has unspecified impact and remote attack vectors related to
"numerous flaws" that are not related to XSS or access control, a
different vulnerability than CVE-2008-4596 and CVE-2008-4597.
|
| CVE-2008-4597 |
Shindig-Integrator 5.x, a module for Drupal, does not properly
restrict generated page access, which allows remote attackers to gain
privileges via unspecified vectors.
|
| CVE-2008-4596 |
Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a
module for Drupal, allows remote authenticated users to inject
arbitrary web script or HTML via unspecified vectors in generated
pages.
|
| CVE-2008-4531 |
SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a
module for Drupal, allows remote attackers to execute arbitrary SQL
commands via unspecified vectors, related to queries. NOTE: this might
be the same issue as CVE-2008-4338.
|
| CVE-2008-4530 |
Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x
before 5.x-4.2, a module for Drupal, allows remote authenticated users
with permissions to inject arbitrary web script or HTML via
unspecified vectors related to posting of answers.
|
| CVE-2008-4338 |
SQL injection vulnerability in the brilliant_gallery_checklist_save
function in the bgchecklist/save script in Brilliant Gallery 5.x and
6.x, a module for Drupal, allows remote authenticated users with
"access brilliant_gallery" permissions to execute arbitrary SQL
commands via the (1) nid, (2) qid, (3) state, and possibly (4) user
parameters.
|
| CVE-2008-4153 |
The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module
for Drupal, does not perform access checks for a node before
displaying comments, which allows remote attackers to obtain sensitive
information.
|
| CVE-2008-4152 |
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before
5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote
authenticated users to inject arbitrary web script or HTML via a node
title.
|
| CVE-2008-4149 |
Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to
Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated
users to inject arbitrary web script or HTML via the "Link page
header" field.
|
| CVE-2008-4148 |
SQL injection vulnerability in the Mailhandler module 5.x before
5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote
attackers to execute arbitrary SQL commands via unspecified vectors,
related to composing queries without using the Drupal database API.
|
| CVE-2008-4147 |
Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x
before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via an e-mail
message with an attached file that has a modified Content-Type.
|
| CVE-2008-3745 |
The Upload module in Drupal 6.x before 6.4 allows remote authenticated
users to edit nodes, delete files, and download unauthorized
attachments via unspecified vectors.
|
| CVE-2008-3744 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal
5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack
the authentication of administrators for requests that (1) add or (2)
delete user access rules.
|
| CVE-2008-3743 |
Multiple cross-site request forgery (CSRF) vulnerabilities in forms in
Drupal 6.x before 6.4 allow remote attackers to perform unspecified
actions via unknown vectors, related to improper token validation for
(1) cached forms and (2) forms with AHAH elements.
|
| CVE-2008-3742 |
Unrestricted file upload vulnerability in the BlogAPI module in Drupal
5.x before 5.10 and 6.x before 6.4 allows remote authenticated users
to execute arbitrary code by uploading a file with an executable
extension, which is not validated.
|
| CVE-2008-3741 |
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4
trusts the MIME type sent by a web browser, which allows remote
authenticated users to conduct cross-site scripting (XSS) attacks by
uploading files containing arbitrary web script or HTML.
|
| CVE-2008-3740 |
Cross-site scripting (XSS) vulnerability in the output filter in
Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-3661 |
Drupal, probably 5.10 and 6.4, does not set the secure flag for the
session cookie in an https session, which can cause the cookie to be
sent in http requests and make it easier for remote attackers to
capture this cookie.
|
| CVE-2008-3500 |
Cross-site scripting (XSS) vulnerability in the Suggested Terms module
5.x before 5.x-1.2 for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via crafted Taxonomy terms.
|
| CVE-2008-3223 |
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3
allows remote attackers to execute arbitrary SQL commands via vectors
related to "an inappropriate placeholder for 'numeric' fields."
|
| CVE-2008-3222 |
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before
6.3, when contributed modules "terminate the current request during a
login event," allows remote attackers to hijack web sessions via
unknown vectors.
|
| CVE-2008-3221 |
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before
6.3 allows remote attackers to perform administrative actions via
vectors involving deletion of OpenID identities.
|
| CVE-2008-3220 |
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before
5.8 and 6.x before 6.3 allows remote attackers to perform
administrative actions via vectors involving deletion of "translated
strings."
|
| CVE-2008-3219 |
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before
6.3 does not "prevent use of the object HTML tag in administrator
input," which has unknown impact and attack vectors, probably related
to an insufficient cross-site scripting (XSS) protection mechanism.
|
| CVE-2008-3218 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x
before 6.3 allow remote attackers to inject arbitrary web script or
HTML via vectors related to (1) free tagging taxonomy terms, which are
not properly handled on node preview pages, and (2) unspecified OpenID
values.
|
| CVE-2008-3097 |
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka
Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote
authenticated users to inject arbitrary web script or HTML, probably
by creating a crafted taxonomy term.
|
| CVE-2008-3096 |
The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each
content reader's authentication level to match that of the content
author, which might allow remote attackers to gain privileges.
|
| CVE-2008-3095 |
Cross-site scripting (XSS) vulnerability in the Organic Groups (OG)
module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for
Drupal, allows remote authenticated users, with group owner
permissions, to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-3094 |
The Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before
6.x-1.0-RC1, a module for Drupal, allows remote attackers to obtain
sensitive information (private group names) via unspecified vectors.
|
| CVE-2008-3092 |
SQL injection vulnerability in the Taxonomy Autotagger module 5.x
before 5.x-1.8 for Drupal allows remote authenticated users, with
create or edit post permissions, to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2008-3091 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger
module 5.x before 5.x-1.8 for Drupal allows remote authenticated
users, with create or edit post permissions, to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-3001 |
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote
attackers to upload files with arbitrary extensions, and possibly
execute arbitrary code, via a crafted feed that allows upload of files
with arbitrary extensions.
|
| CVE-2008-3000 |
The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access
modules are used, does not properly implement access control, which
allows remote attackers to bypass intended restrictions.
|
| CVE-2008-2999 |
Multiple SQL injection vulnerabilities in the Aggregation module 5.x
before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary
SQL commands via unspecified vectors.
|
| CVE-2008-2998 |
Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation
module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2008-2850 |
SQL injection vulnerability in the TrailScout module 5.x before
5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL
commands via unspecified cookies, related to improper use of the
Drupal database API.
|
| CVE-2008-2849 |
Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x
before 5.x-1.4 for Drupal allows remote authenticated users, with
create post permissions, to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2773 |
Cross-site scripting (XSS) vulnerability in the Taxonomy Image module
5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2008-2772 |
The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote
attackers to execute arbitrary PHP code via unspecified URL arguments,
possibly related to a missing "whitelist of callbacks."
|
| CVE-2008-2771 |
The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0
for Drupal does not properly implement access checks, which allows
remote attackers with "access content" permissions to bypass
restrictions and modify the node hierarchy via unspecified attack
vectors.
|
| CVE-2008-2629 |
SQL injection vulnerability in the LifeType (formerly pLog) module for
Drupal allows remote attackers to execute arbitrary SQL commands via
the albumId parameter in a ViewAlbum action to index.php.
|
| CVE-2008-2271 |
The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before
6.x-1.1 allows remote authenticated users to gain privileges of other
users by leveraging the "access content" permission to list tables and
obtain session IDs from the database.
|
| CVE-2008-1981 |
Cross-site request forgery (CSRF) vulnerability in E-Publish 5.x
before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows
remote attackers to perform unauthorized actions as other users via
unspecified vectors.
|
| CVE-2008-1980 |
Cross-site scripting (XSS) vulnerability in E-Publish 5.x before
5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2008-1978 |
Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before
5.x-1.0 rc3 module for Drupal allows remote authenticated users to
inject arbitrary web script or HTML via node titles related to
unspecified product features, a different vector than CVE-2008-1428.
|
| CVE-2008-1977 |
Cross-site request forgery (CSRF) vulnerability in the
Internationalization (i18n) Drupal module 5.x before 5.x-2.3 and
5.x-1.1, and 6.x before 6.x-1.0 beta 1, allows remote attackers to
change node translation relationships via unspecified vectors.
|
| CVE-2008-1976 |
Multiple cross-site scripting (XSS) vulnerabilities in the Drupal
modules (1) Internationalization (i18n) 5.x before 5.x-2.3 and 5.x-1.1
and 6.x before 6.x-1.0 beta 1; and (2) Localizer 5.x before 5.x-3.4,
5.x-2.1, and 5.x-1.11; allow remote attackers to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2008-1916 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart
5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to
inject arbitrary web script or HTML via text fields intended for the
(1) address and (2) order information, which are later displayed on
the order view page and unspecified other administrative pages, a
different vulnerability than CVE-2008-1428.
|
| CVE-2008-1794 |
Multiple cross-site scripting (XSS) vulnerabilities in the Webform
Drupal module 5.x before 5.x-1.10, 5.x-2.x before 5.x-2.0-beta3, and
6.x before 6.x-1.0-beta3 allow remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-1792 |
Cross-site scripting (XSS) vulnerability in the insertion filter in
the Flickr Drupal module 5.x before 5.x-1.3 and 6.x before
6.x-1.0-alpha allows remote attackers to inject arbitrary web script
or HTML via unspecified vectors.
|
| CVE-2008-1731 |
The Simple Access module for Drupal 5.x through 5.x-1.2-2 does not
properly handle the privacy information for nodes, which might allow
remote attackers to bypass intended access restrictions, and read or
modify nodes, in opportunistic circumstances related to interaction
between Simple Access and (1) Node clone or (2) Project issue
tracking.
|
| CVE-2008-1729 |
The menu system in Drupal 6 before 6.2 has incorrect menu settings,
which allows remote attackers to (1) edit the profile pages of
arbitrary users, and obtain sensitive information from (2) tracker and
(3) blog pages, related to a missing check for the "access content"
permission; and (4) allows remote authenticated users, with
administration page view access, to edit content types.
|
| CVE-2008-1428 |
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart
5.x before 5.x-1.0-beta7 module for Drupal allow remote attackers to
inject arbitrary web script or HTML via a text attribute value for a
product.
|
| CVE-2008-1133 |
The Drupal.checkPlain function in Drupal 6.0 only escapes the first
instance of a character in ECMAScript, which allows remote attackers
to conduct cross-site scripting (XSS) attacks.
|
| CVE-2008-1131 |
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote
authenticated users to inject arbitrary web script or HTML via titles
in content edit forms.
|
| CVE-2008-0823 |
Unspecified vulnerability in the Header Image Module before 5.x-1.1
for Drupal allows remote attackers to access the administration pages
via unknown attack vectors.
|
| CVE-2008-0577 |
The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the
5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6
and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the
4.7.x-1.x series for Drupal (1) does not restrict the extensions of
attached files when the Upload module is enabled for issue nodes,
which allows remote attackers to upload and possibly execute arbitrary
files; and (2) accepts the .html extension within the bundled
file-upload functionality, which allows remote attackers to upload
files containing arbitrary web script or HTML.
|
| CVE-2008-0576 |
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking
module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and
earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x
series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal
allows remote authenticated users to inject arbitrary web script or
HTML via unspecified vectors that write to summary table pages.
|
| CVE-2008-0571 |
The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3,
5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does
not follow Drupal's Forms API submission model, which allows remote
attackers to conduct cross-site request forgery (CSRF) attacks and
manipulate points.
|
| CVE-2008-0570 |
The OpenID 5.x-1.0 and earlier module for Drupal does not properly
verify the claimed_id returned by an OpenID provider, which allows
remote OpenID providers to spoof OpenID authentication for domains
associated with other providers.
|
| CVE-2008-0569 |
The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1
module for Drupal does not properly use functions in the upload
module, which allows remote attackers to bypass upload validation, and
upload arbitrary files and possibly execute arbitrary code, via
unspecified vectors.
|
| CVE-2008-0568 |
Unspecified vulnerability in the IP-authentication feature in the
Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote
attackers to gain the privileges of a user who has authenticated from
behind the same proxy server as the attacker.
|
| CVE-2008-0463 |
Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before
4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors involving node properties.
|
| CVE-2008-0462 |
Cross-site scripting (XSS) vulnerability in the Archive 5.x before
5.x-1.8 module for Drupal allows remote attackers to inject arbitrary
web script or HTML via unspecified vectors.
|
| CVE-2008-0277 |
Unspecified vulnerability in the Fileshare module for Drupal allows
remote authenticated users with node-creation privileges to execute
arbitrary code via unspecified vectors.
|
| CVE-2008-0276 |
Cross-site scripting (XSS) vulnerability in the Devel module before
5.x-0.1 for Drupal allows remote attackers to inject arbitrary web
script or HTML via a site variable, related to lack of escaping of the
variable table.
|
| CVE-2008-0275 |
The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal
does not properly manage permissions for node (1) titles, (2) teasers,
and (3) bodies, which might allow remote attackers to gain access to
syndicated content.
|
| CVE-2008-0274 |
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when
certain .htaccess protections are disabled, allows remote attackers to
inject arbitrary web script or HTML via crafted links involving theme
.tpl.php files.
|
| CVE-2008-0273 |
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before
5.6, when Internet Explorer 6 is used, allows remote attackers to
conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte
sequences, which are not processed as UTF-8 by Drupal's HTML
filtering, but are processed as UTF-8 by Internet Explorer,
effectively removing characters from the document and defeating the
HTML protection mechanism.
|
| CVE-2008-0272 |
Cross-site request forgery (CSRF) vulnerability in the aggregator
module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote
attackers to delete items from a feed as privileged users.
|
| CVE-2008-0271 |
The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x
before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms
API submission model, which allows remote attackers to conduct
cross-site request forgery (CSRF) attacks and delete custom editor
interfaces.
|
| CVE-2008-0264 |
Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6
module for Drupal, when images are permitted in node bodies, allows
remote authenticated users to execute arbitrary code via unspecified
vectors involving creation of a node.
|
| CVE-2007-6752 |
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in
Drupal 7.12 and earlier allows remote attackers to hijack the
authentication of arbitrary users for requests that end a session via
the user/logout URI. NOTE: the vendor disputes the significance of
this issue, by considering the "security benefit against platform
complexity and performance impact" and concluding that a change to the
logout behavior is not planned because "for most sites it is not worth
the trade-off."
|
| CVE-2007-6320 |
Feature 4.7.x-dev and 5.x-dev before 20071206, a Drupal module, does
not follow Drupal's Forms API submission model, which allows remote
attackers to conduct cross-site request forgery (CSRF) attacks.
|
| CVE-2007-6299 |
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x
before 4.7.9 and 5.x before 5.4 allow remote attackers to execute
arbitrary SQL commands via modules that pass input to the
taxonomy_select_nodes function, as demonstrated by the (1)
taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
|
| CVE-2007-6298 |
Cross-site scripting (XSS) vulnerability in the Shoutbox module for
Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users
to inject arbitrary web script or HTML via Shoutbox block messages.
|
| CVE-2007-5621 |
Multiple cross-site scripting (XSS) vulnerabilities in the Token
module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used
by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node
Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote
authenticated users with a post comments privilege to inject arbitrary
web script or HTML via unspecified vectors related to (1) comments,
(2) vocabulary names, (3) term names, and (4) usernames.
|
| CVE-2007-5598 |
Cross-site scripting (XSS) vulnerability in Weblinks for Drupal 4.7.x
before 4.7.x-1.0 and 5.x before 5.x-1.8 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2007-5597 |
The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3
does not pass publication status, which might allow attackers to
bypass access restrictions and trigger e-mail with unpublished
comments from some modules, as demonstrated by (1) Organic groups and
(2) Subscriptions.
|
| CVE-2007-5596 |
The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3
places the .html extension on a whitelist, which allows remote
attackers to conduct cross-site scripting (XSS) attacks by uploading
.html files.
|
| CVE-2007-5595 |
CRLF injection vulnerability in the drupal_goto function in
includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3
allows remote attackers to inject arbitrary HTTP headers and conduct
HTTP response splitting attacks via unspecified vectors.
|
| CVE-2007-5594 |
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection
against the user deletion form, which allows remote attackers to
delete users via a cross-site request forgery (CSRF) attack.
|
| CVE-2007-5593 |
install.php in Drupal 5.x before 5.3, when the configured database
server is not reachable, allows remote attackers to execute arbitrary
code via vectors that cause settings.php to be modified.
|
| CVE-2007-5416 |
Drupal 5.2 and earlier does not properly unset variables when the
input data includes a numeric parameter with a value matching an
alphanumeric parameter's hash value, which allows remote attackers to
execute arbitrary PHP code by invoking the drupal_eval function
through a callback parameter to the default URI, as demonstrated by
the _menu[callbacks][1][callback] parameter. NOTE: it could be argued
that this vulnerability is due to a bug in the unset PHP command
(CVE-2006-3017) and the proper fix should be in PHP; if so, then this
should not be treated as a vulnerability in Drupal.
|
| CVE-2007-5270 |
Unspecified vulnerability in the Boost module before 4.7.x-1.0, and
5.x before 5.x-1.0, for Drupal allows remote attackers to create or
overwrite arbitrary files, and conduct cross-site scripting attacks
(XSS) via unspecified vectors.
|
| CVE-2007-5228 |
Cross-site scripting (XSS) vulnerability in the subscription
functionality in the Project issue tracking module before 4.7.x-1.5,
4.7.x-2.x before 4.7.x-2.5, and 5.x-1.x before 5.x-1.1 for Drupal
allows remote authenticated users with project create or edit
permissions to inject arbitrary web script or HTML via unspecified
vectors involving a (1) individual or (2) overview form.
|
| CVE-2007-4436 |
The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and
Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4
do not properly enforce permissions, which allows remote attackers to
(1) obtain sensitive via the Tracker Module and the Recent posts page;
(2) obtain project names via unspecified vectors; (3) obtain sensitive
information via the statistics pages; and (4) read CVS project
activity.
|
| CVE-2007-4363 |
Multiple cross-site scripting (XSS) vulnerabilities in the
nodereference module in Drupal Content Construction Kit (CCK) before
4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject
arbitrary web script or HTML via nodereference fields, when using (1)
the plain formatter or (2) the autocomplete text field widget without
Views.module.
|
| CVE-2007-4064 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x
before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to
inject arbitrary web script or HTML via "some server variables,"
including PHP_SELF; and (2) allow remote authenticated administrators
to inject arbitrary web script or HTML via custom content type names.
|
| CVE-2007-4063 |
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal
5.x before 5.2 allow remote attackers to (1) delete comments, (2)
delete content revisions, and (3) disable menu items as privileged
users, related to improper use of HTTP GET and the Forms API.
|
| CVE-2007-3818 |
Cross-site scripting (XSS) vulnerability in the LoginToboggan module
5.x-1.x-dev before 20070712 for Drupal allows remote authenticated
users with "administer blocks" permission to inject arbitrary
JavaScript and gain privileges via "the message displayed above the
default user login block."
|
| CVE-2007-3817 |
Cross-site scripting (XSS) vulnerability in the LoginToboggan module
4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal,
when configured to display a "Log out" link, allows remote attackers
to inject arbitrary web script or HTML via a crafted username. NOTE:
Drupal sanitizes the username by removing certain characters, so this
might not be a vulnerability on default installations.
|
| CVE-2007-3690 |
The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal
allows remote attackers to read restricted posts in (1) Organic
Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and
other unspecified node access modules, via modified URL arguments.
|
| CVE-2007-3689 |
The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal
allows remote attackers to read restricted posts in (1) Organic
Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and
other unspecified node access modules, via modified URL arguments.
|
| CVE-2007-2160 |
Multiple cross-site request forgery (CSRF) vulnerabilities in the
Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in
the 4.7.x-1.* series, for Drupal allow remote attackers to perform
unauthorized actions as an arbitrary user, a related issue to
CVE-2006-5476.
|
| CVE-2007-2159 |
Multiple cross-site scripting (XSS) vulnerabilities in the Database
Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the
4.7.x-1.* series, for Drupal allow remote attackers to inject
arbitrary web script or HTML via unspecified vectors relating to (1)
direct display of data from the database and (2) other portions of the
user interface.
|
| CVE-2007-1368 |
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before
4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote
authenticated users, with "access project issues" permission, to read
the contents of a private node via a URL with a modified node
identifier.
|
| CVE-2007-1360 |
Unspecified vulnerability in the Nodefamily module for Drupal 5.x
before 5.x-1.0 allows remote authenticated users to access and modify
other users' profiles via unspecified URL parameters.
|
| CVE-2007-1035 |
Unspecified vulnerability in certain demonstration scripts in getID3
1.7.1, as used in the Mediafield and Audio modules for Drupal, allows
remote attackers to read and delete arbitrary files, list arbitrary
directories, and write to empty files or .mp3 files via unknown
vectors.
|
| CVE-2007-1033 |
Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and
5.x-1.x-dev module for Drupal allows remote attackers to bypass
access restrictions via a crafted URL.
|
| CVE-2007-1028 |
Cross-site scripting (XSS) vulnerability in the Barry Jaspan Image
Pager 4.7.x-1.x-dev and 5.x-1.x-dev before 2007-02-08 module for
Drupal allows remote attackers to inject arbitrary web script or HTML
via unspecified vectors related to HTML entities and the IMG element.
|
| CVE-2007-0841 |
Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have
unknown impact and remote attack vectors. NOTE: the vector related to
Drupal is covered by CVE-2007-0626. These vulnerabilities might be
associated with other CVE identifiers.
|
| CVE-2007-0658 |
The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module
for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before
5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA
test via an empty captcha element in $_SESSION.
|
| CVE-2007-0626 |
The comment_form_add_preview function in comment.module in Drupal
before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote
attackers with "post comments" privileges and access to multiple input
filters to execute arbitrary code by previewing comments, which are
not processed by "normal form validation routines."
|
| CVE-2007-0534 |
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project
issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0
through 5.x before 20070123 modules for Drupal allow remote
authenticated users to inject arbitrary web script or HTML via (a)
certain "fields on project nodes" or (b) "certain project-specific
settings regarding issue tracking."
|
| CVE-2007-0507 |
SQL injection vulnerability in the Acidfree module for Drupal before
4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote
authenticated users with "create acidfree albums" privileges to
execute arbitrary SQL commands via node titles.
|
| CVE-2007-0506 |
The project_issue_access function in the Project issue tracking 4.7.0
through 5.x before 20070123 module for Drupal allows remote
authenticated users to bypass other access control modules and obtain
attached files by guessing the filename, and obtain issue information
via direct requests.
|
| CVE-2007-0505 |
Unrestricted file upload vulnerability in the Project issue tracking
4.7.0 through 5.x before 20070123, a module for Drupal, allows remote
authenticated users to execute arbitrary code by attaching a file with
executable or multiple extensions to a project issue.
|
| CVE-2007-0136 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal before
4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters in the (1)
filter and (2) system modules. NOTE: some of these details are
obtained from third party information.
|
| CVE-2007-0124 |
Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before
4.7.5, when MySQL is used, allows remote authenticated users to cause
a denial of service by poisoning the page cache via unspecified
vectors, which triggers erroneous 404 HTTP errors for pages that
exist.
|
| CVE-2006-7110 |
Directory traversal vulnerability in the delete function in IMCE
before 1.6, a Drupal module, allows remote authenticated users to
delete arbitrary files via ".." sequences.
|
| CVE-2006-7109 |
Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal
module, allows remote authenticated users to upload arbitrary PHP code
via a filename with a double extension such as .php.gif.
|
| CVE-2006-6647 |
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before
4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote
attackers to inject arbitrary web script or HTML via the Title field
when editing a page. NOTE: some details were obtained from third party
information.
|
| CVE-2006-6646 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1)
Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project
4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject
arbitrary web script or HTML via unspecified parameters, which do not
use the check_plain function.
|
| CVE-2006-6531 |
Cross-site scripting (XSS) vulnerability in the Help Tip module before
4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web
script or HTML, and possibly obtain administrative access, via node
titles.
|
| CVE-2006-6530 |
SQL injection vulnerability in the Help Tip module before 4.7.x-1.0
for Drupal allows remote attackers to execute arbitrary SQL commands
via unspecified vectors.
|
| CVE-2006-6529 |
The Chatroom Module before 4.7.x.-1.0 for Drupal displays private
messages in a chatroom's last messages overview, which allows remote
attackers to obtain sensitive information by reading the overview.
|
| CVE-2006-6528 |
The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom
visitors' session IDs to all participants, which allows remote
attackers to hijack sessions and gain privileges.
|
| CVE-2006-6386 |
Cross-site scripting (XSS) vulnerability in the CVS management/tracker
4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution
release system) for Drupal allows remote attackers to inject arbitrary
web script or HTML via the motivation field in the CVS application
page, which is not passed through check_markup on display.
|
| CVE-2006-5608 |
SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before
1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL
commands via unspecified vectors related to "parameters from URLs."
|
| CVE-2006-5477 |
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form
submissions to be redirected, which allows remote attackers to obtain
arbitrary form information via a crafted URL.
|
| CVE-2006-5476 |
Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before
4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform
unauthorized actions as an arbitrary user via unspecified vectors.
|
| CVE-2006-5475 |
Multiple cross-site scripting (XSS) vulnerabilities in the XML parser
in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote
attackers to inject arbitrary web script or HTML via a crafted RSS
feed.
|
| CVE-2006-4949 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.6 Site
Profile Directory (profile_pages.module) before 1.1.2.1 and the Drupal
4.7 Site Profile Directory (profile_pages.module) before 1.2.2.1
allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors related to "lack of validation on output,"
possibly in the name and title parameters.
|
| CVE-2006-4947 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search
Keywords module before 1.15 2006/09/15 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors related to
"lack of validation on output."
|
| CVE-2006-4821 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview
module before 1.19 2006/09/12 allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4717 |
The login redirection mechanism in the Drupal 4.7 Pubcookie module
before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before
1.6.2.1 2006/09/07 allows remote attackers to bypass authentication
requirements and spoof identities of arbitrary users via unspecified
vectors.
|
| CVE-2006-4646 |
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto
module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto
module before pathauto_node.inc 1.14.2.1 allows remote attackers to
inject arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4360 |
Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal
before file.module 1.37.2.4 (20060812) allows remote authenticated
users with the "create products" permission to inject arbitrary web
script or HTML via unspecified vectors.
|
| CVE-2006-4356 |
SQL injection vulnerability in Drupal Easylinks Module
(easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows
remote attackers to execute arbitrary SQL commands via unspecified
vectors.
|
| CVE-2006-4355 |
Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module
(easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-4120 |
Cross-site scripting (XSS) vulnerability in the Recipe module
(recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote
attackers to inject arbitrary web script or HTML via unspecified
vectors.
|
| CVE-2006-4109 |
Cross-site scripting (XSS) vulnerability in Bibliography
(biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before
revision 1.13.2.5 for Drupal allows remote attackers to inject
arbitrary web script or HTML via unspecified vectors.
|
| CVE-2006-4108 |
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before
revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal
allows remote attackers to execute arbitrary SQL commands via
unspecified vectors.
|
| CVE-2006-4107 |
SQL injection vulnerability in the Job Search module (job.module) 4.6
before revision 1.3.2.1 in Drupal allows remote attackers to execute
arbitrary SQL commands via a job or resume search.
|
| CVE-2006-4002 |
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6
before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject
arbitrary web script or HTML via the msg parameter. NOTE: portions of
these details are obtained from third party information.
|
| CVE-2006-3570 |
Cross-site scripting (XSS) vulnerability in the webform module in
Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows
remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
|
| CVE-2006-3473 |
CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2
allows remote attackers to inject e-mail headers, which facilitates
sending spam messages, a different issue than CVE-2006-1225.
|
| CVE-2006-2833 |
Cross-site scripting (XSS) vulnerability in the taxonomy module in
Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web
script or HTML via inputs that are not properly validated when the
page title is output, possibly involving the $names variable.
|
| CVE-2006-2832 |
Cross-site scripting (XSS) vulnerability in the upload module
(upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2
allows remote attackers to inject arbitrary web script or HTML via the
uploaded filename.
|
| CVE-2006-2831 |
Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under
certain Apache configurations such as when FileInfo overrides are
disabled within .htaccess, allows remote attackers to execute
arbitrary code by uploading a file with multiple extensions, a variant
of CVE-2006-2743.
|
| CVE-2006-2743 |
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with
mod_mime, does not properly handle files with multiple extensions,
which allows remote attackers to upload, modify, or execute arbitrary
files in the files directory.
|
| CVE-2006-2742 |
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0
allows remote attackers to execute arbitrary SQL commands via the (1)
count and (2) from variables to (a) database.mysql.inc, (b)
database.pgsql.inc, and (c) database.mysqli.inc.
|
| CVE-2006-2260 |
Cross-site scripting (XSS) vulnerability in the project module
(project.module) in Drupal 4.5 and 4.6 allows remote attackers to
inject arbitrary web script or HTML via unknown attack vectors.
|
| CVE-2006-1228 |
Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x
before 4.5.8 allows remote attackers to gain privileges by tricking a
user to click on a URL that fixes the session identifier.
|
| CVE-2006-1227 |
Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is
used to create a menu item, does not implement access control for the
page that is referenced, which might allow remote attackers to access
administrator pages.
|
| CVE-2006-1226 |
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8
and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web
script or HTML via unknown attack vectors.
|
| CVE-2006-1225 |
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x
before 4.5.8 allows remote attackers to inject headers of outgoing
e-mail messages and use Drupal as a spam proxy.
|
| CVE-2006-0070 |
** DISPUTED **
Drupal allows remote attackers to conduct cross-site scripting (XSS)
attacks via an IMG tag with an unusual encoded Javascript function
name, as demonstrated using variations of the alert() function. NOTE:
a followup by the vendor suggests that the issue does not exist in
4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML"
would not filter HTML by design, perhaps this should not be included
in CVE.
|
| CVE-2005-3975 |
Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and
4.6.0 through 4.6.3 allows remote authenticated users to inject
arbitrary web script or HTML via HTML in a file with a GIF or JPEG
file extension, which causes the HTML to be executed by a victim who
views the file in Internet Explorer as a result of CVE-2005-3312.
NOTE: it could be argued that this vulnerability is due to a design
flaw in Internet Explorer and the proper fix should be in that
browser; if so, then this should not be treated as a vulnerability in
Drupal.
|
| CVE-2005-3974 |
Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on
PHP5, does not correctly enforce user privileges, which allows remote
attackers to bypass the "access user profiles" permission.
|
| CVE-2005-3973 |
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0
through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject
arbitrary web script or HTML via various HTML tags and values, such as
the (1) legend tag and the value parameter used in (2) label and (3)
input tags, possibly due to an incomplete blacklist.
|
| CVE-2005-2498 |
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR
XML-RPC for PHP), as used in multiple products including (1) Drupal,
(2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote
attackers to execute arbitrary PHP code via certain nested XML tags in
a PHP document that should not be nested, which are injected into an
eval function call, a different vulnerability than CVE-2005-1921.
|
| CVE-2005-2106 |
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1
allows remote attackers to execute arbitrary PHP code via a public
comment or posting.
|
| CVE-2005-1921 |
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka
XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc)
1.1 and earlier, as used in products such as (1) WordPress, (2)
Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki,
(7) phpWebSite, (8) Ampache, and others, allows remote attackers to
execute arbitrary PHP code via an XML file, which is not properly
sanitized before being used in an eval statement.
|
| CVE-2005-1871 |
Unknown vulnerability in the privilege system in Drupal 4.4.0 through
4.6.0, when public registration is enabled, allows remote attackers to
gain privileges, due to an "input check" that "is not implemented
properly."
|
| CVE-2005-0682 |
Cross-site scripting (XSS) vulnerability in common.inc in Drupal
before 4.5.2 allows remote attackers to inject arbitrary web script or
HTML via certain inputs.
|
| CVE-2002-1806 |
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote
attackers to inject arbitrary web script or HTML via Javascript in an
IMG tag.
|