Lucene search

K

Filefield Security Vulnerabilities

cve
cve

CVE-2014-9156

The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded...

6.3AI Score

0.002EPSS

2022-10-03 04:20 PM
19
cve
cve

CVE-2012-5538

Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded...

5.5AI Score

0.001EPSS

2022-10-03 04:15 PM
21
cve
cve

CVE-2013-4502

The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a...

6.5AI Score

0.002EPSS

2014-05-13 03:55 PM
28
cve
cve

CVE-2010-1958

Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name...

5.5AI Score

0.001EPSS

2010-06-21 07:30 PM
22
cve
cve

CVE-2009-3781

The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified...

6.7AI Score

0.013EPSS

2009-10-26 05:30 PM
28