Lucene search

K

Search Autocomplete Security Vulnerabilities

cve
cve

CVE-2012-1638

SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified vectors.

8.1AI Score

0.002EPSS

2012-09-19 09:55 PM
29
cve
cve

CVE-2012-4471

The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.

6.9AI Score

0.003EPSS

2012-11-30 10:55 PM
25