Lucene search

K

Content Construction Kit Security Vulnerabilities

cve
cve

CVE-2015-5510

Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration...

7AI Score

0.003EPSS

2015-08-18 06:00 PM
25
cve
cve

CVE-2009-1069

Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference...

5.8AI Score

0.003EPSS

2009-03-26 05:51 AM
24
cve
cve

CVE-2008-6229

Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1).....

5.4AI Score

0.001EPSS

2009-02-20 11:30 PM
18
cve
cve

CVE-2007-4363

Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the...

5.8AI Score

0.03EPSS

2007-08-15 07:17 PM
20