Lucene search

K

Drupal Project Security Vulnerabilities

cve
cve

CVE-2012-4489

Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q...

6.9AI Score

0.006EPSS

2012-10-31 04:55 PM
18
cve
cve

CVE-2012-4495

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as...

6.6AI Score

0.002EPSS

2012-10-31 04:55 PM
21
cve
cve

CVE-2012-4485

Multiple cross-site scripting (XSS) vulnerabilities in the galleryformatter_field_formatter_view functiuon in galleryformatter.tpl.php the Gallery formatter module before 7.x-1.2 for Drupal allow remote authenticated users with permissions to create a node or entity to inject arbitrary web script.....

5.5AI Score

0.002EPSS

2012-10-31 04:55 PM
23
cve
cve

CVE-2012-1634

Cross-site scripting (XSS) vulnerability in video_filter.codecs.inc in the Video Filter module 6.x-2.x and 7.x-2.x for Drupal allows remote attackers to inject arbitrary web script or HTML via the EMBEDLOOKUP parameter for Blip.tv...

5.9AI Score

0.004EPSS

2012-10-06 09:55 PM
30
cve
cve

CVE-2012-1639

Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title...

5.5AI Score

0.001EPSS

2012-10-01 08:55 PM
26
cve
cve

CVE-2012-2153

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content...

6AI Score

0.002EPSS

2012-10-01 12:55 AM
23
cve
cve

CVE-2012-1591

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image...

6.5AI Score

0.006EPSS

2012-10-01 12:55 AM
21
cve
cve

CVE-2012-1590

The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview...

5.8AI Score

0.003EPSS

2012-10-01 12:55 AM
33
cve
cve

CVE-2012-1588

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email...

6.2AI Score

0.01EPSS

2012-10-01 12:55 AM
19
cve
cve

CVE-2012-1633

Cross-site request forgery (CSRF) vulnerability in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote attackers to hijack the authentication of administrative users for requests that unblock a...

7.3AI Score

0.006EPSS

2012-09-20 12:55 AM
19
cve
cve

CVE-2012-1640

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a...

5.5AI Score

0.001EPSS

2012-09-19 09:55 PM
26
cve
cve

CVE-2012-1652

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "the vocabulary's help...

5.4AI Score

0.001EPSS

2012-09-19 07:55 PM
18
cve
cve

CVE-2012-1660

Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject...

5.4AI Score

0.001EPSS

2012-09-18 08:55 PM
18
cve
cve

CVE-2012-1659

Cross-site scripting (XSS) vulnerability in the Node Recommendation module 6.x-1.x before 6.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2012-09-18 08:55 PM
20
cve
cve

CVE-2012-1657

Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the class...

5.5AI Score

0.001EPSS

2012-09-18 08:55 PM
18
cve
cve

CVE-2012-2069

Cross-site request forgery (CSRF) vulnerability in the Wishlist module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences via the (1) wl_reveal or (2) q...

6.6AI Score

0.006EPSS

2012-09-06 05:55 PM
25
cve
cve

CVE-2012-2068

Multiple cross-site scripting (XSS) vulnerabilities in fancy_slide.module in the Fancy Slide module before 6.x-2.7 for Drupal allow remote authenticated users with the administer fancy_slide permission to inject arbitrary web script or HTML via the (1) node_title or (2) nodequeue_title...

5.5AI Score

0.001EPSS

2012-09-05 12:55 AM
21
cve
cve

CVE-2012-2063

The Slidebox module before 7.x-1.4 for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspecified...

6.4AI Score

0.006EPSS

2012-09-05 12:55 AM
22
4
cve
cve

CVE-2012-2704

The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which allows remote attackers to obtain sensitive site configuration information that is specified by the $conf variable in...

6.3AI Score

0.007EPSS

2012-08-31 08:55 PM
18
cve
cve

CVE-2012-1650

The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access...

6.5AI Score

0.004EPSS

2012-08-28 05:55 PM
20
cve
cve

CVE-2012-1644

The Organic Groups (OG) Vocabulary module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with certain administrator permissions to modify the vocabularies of other groups via unspecified...

6.4AI Score

0.004EPSS

2012-08-28 05:55 PM
28
cve
cve

CVE-2012-1647

Multiple cross-site scripting (XSS) vulnerabilities in the "stand alone PHP application for the OSM Player," as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal, allow remote attackers to inject arbitrary web script or HTML via (1) $_SERVER['HTTP_HOST'] or....

6AI Score

0.005EPSS

2012-08-28 05:55 PM
27
cve
cve

CVE-2012-2297

Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creativecommons_user_message or (2)...

5.5AI Score

0.001EPSS

2012-08-26 09:55 PM
23
cve
cve

CVE-2012-2070

Cross-site scripting (XSS) vulnerability in the MultiBlock module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer blocks permission to inject arbitrary web script or HTML via the block...

5.5AI Score

0.001EPSS

2012-08-14 11:55 PM
17
cve
cve

CVE-2012-2077

Cross-site request forgery (CSRF) vulnerability in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of users with administer sharethis permissions via unknown vectors "outside of the Form...

7.2AI Score

0.003EPSS

2012-08-14 11:55 PM
22
cve
cve

CVE-2012-2073

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified...

7.5AI Score

0.004EPSS

2012-08-14 11:55 PM
21
4
cve
cve

CVE-2012-2074

Unspecified vulnerability in certain default views in the Ubercart Views module 6.x before 6.x-3.2 for Drupal allows remote attackers to obtain sensitive information via unknown attack...

6.3AI Score

0.006EPSS

2012-08-14 11:55 PM
20
cve
cve

CVE-2012-2076

Cross-site scripting (XSS) vulnerability in the administration forms in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with administer sharethis permissions to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2012-08-14 11:55 PM
21
cve
cve

CVE-2012-2075

Cross-site scripting (XSS) vulnerability in the Contact Save module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the access site-wide contact form permission to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.001EPSS

2012-08-14 11:55 PM
24
cve
cve

CVE-2012-2080

Cross-site request forgery (CSRF) vulnerability in the Node Limit Number module before 6.x-1.2 for Drupal allows remote attackers to hijack the authentication of users with the administer node limitnumber permission for requests that delete...

7.3AI Score

0.009EPSS

2012-08-14 11:55 PM
19
4
cve
cve

CVE-2012-2298

Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete...

5.8AI Score

0.005EPSS

2012-08-14 10:55 PM
19
cve
cve

CVE-2012-2097

Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests involving "submitting saved results to a...

7.4AI Score

0.009EPSS

2012-08-14 09:55 PM
21
cve
cve

CVE-2012-2303

The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG...

6.6AI Score

0.021EPSS

2012-07-18 06:55 PM
18
cve
cve

CVE-2012-2717

Multiple cross-site scripting (XSS) vulnerabilities in the Mobile Tools module 6.x-2.x before 6.x-2.3 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) Mobile URL field or (2) Desktop URL field to the General configuration page, or the (3) message to the Mobile...

5.9AI Score

0.004EPSS

2012-06-27 09:55 PM
16
cve
cve

CVE-2012-3799

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS)...

6.7AI Score

0.006EPSS

2012-06-27 12:55 AM
18
cve
cve

CVE-2012-3800

Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group...

5.4AI Score

0.001EPSS

2012-06-27 12:55 AM
20
cve
cve

CVE-2012-2722

The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node...

6.9AI Score

0.011EPSS

2012-06-27 12:55 AM
23
cve
cve

CVE-2012-2723

Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with maestro admin permissions to inject arbitrary web script or HTML via unspecified...

5.4AI Score

0.003EPSS

2012-06-27 12:55 AM
19
cve
cve

CVE-2012-2728

Multiple cross-site request forgery (CSRF) vulnerabilities in the Node Hierarchy module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to hijack the authentication of administrators for requests that change a node hierarchy position via an (1) up or (2) down...

7.4AI Score

0.009EPSS

2012-06-27 12:55 AM
20
cve
cve

CVE-2012-2725

classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS)...

5.5AI Score

0.002EPSS

2012-06-27 12:55 AM
26
cve
cve

CVE-2012-2731

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a...

6.4AI Score

0.006EPSS

2012-06-27 12:55 AM
22
cve
cve

CVE-2012-2726

Cross-site scripting (XSS) vulnerability in the Protest module 6.x-1.x before 6.x-1.2 or 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer protest" permission to inject arbitrary web script or HTML via the protest_body...

5.5AI Score

0.001EPSS

2012-06-27 12:55 AM
19
cve
cve

CVE-2012-2713

Cross-site request forgery (CSRF) vulnerability in the BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that login a user to another web...

7.4AI Score

0.011EPSS

2012-06-27 12:55 AM
18
cve
cve

CVE-2012-2715

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of...

5.8AI Score

0.004EPSS

2012-06-27 12:55 AM
19
cve
cve

CVE-2012-2721

The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified...

7.1AI Score

0.033EPSS

2012-06-27 12:55 AM
20
cve
cve

CVE-2012-2708

Cross-site scripting (XSS) vulnerability in the _hosting_task_log_table function in modules/hosting/task/hosting_task.module in the Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a...

5.4AI Score

0.001EPSS

2012-06-27 12:55 AM
24
cve
cve

CVE-2012-2712

Multiple cross-site scripting (XSS) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.1 for Drupal, when supporting manual entry of field identifiers, allow remote attackers to inject arbitrary web script or HTML via vectors related to thrown exceptions and logging...

5.8AI Score

0.004EPSS

2012-06-27 12:55 AM
19
cve
cve

CVE-2012-2711

Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy List module 6.x-1.x before 6.x-1.4 for Drupal allow remote authenticated users with create or edit taxonomy terms permissions to inject arbitrary web script or HTML via vectors related to taxonomy...

5.4AI Score

0.001EPSS

2012-06-27 12:55 AM
19
cve
cve

CVE-2012-2705

The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title...

5.6AI Score

0.002EPSS

2012-06-27 12:55 AM
616
cve
cve

CVE-2012-2707

The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does not properly exit when users do not have access to package/task nodes, which allows remote attackers to bypass intended access restrictions and edit unauthorized...

7AI Score

0.03EPSS

2012-06-27 12:55 AM
20
Total number of security vulnerabilities168