Lucene search

K

Drupal Security Vulnerabilities

cve
cve

CVE-2002-1806

Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

6AI Score

0.003EPSS

2022-10-03 04:23 PM
27
cve
cve

CVE-2005-0682

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

5.7AI Score

0.002EPSS

2005-05-02 04:00 AM
23
cve
cve

CVE-2005-1871

Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."

6.9AI Score

0.011EPSS

2005-06-09 04:00 AM
30
cve
cve

CVE-2005-1921

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache,...

7.6AI Score

0.956EPSS

2005-07-05 04:00 AM
134
cve
cve

CVE-2005-2106

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

7.3AI Score

0.032EPSS

2005-07-05 04:00 AM
37
cve
cve

CVE-2005-3973

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly...

5.8AI Score

0.004EPSS

2005-12-03 07:03 PM
29
cve
cve

CVE-2005-3974

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

6.5AI Score

0.005EPSS

2005-12-03 07:03 PM
35
cve
cve

CVE-2005-3975

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Ex...

5.7AI Score

0.823EPSS

2005-12-03 07:03 PM
26
cve
cve

CVE-2006-0070

Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filte...

5.7AI Score

0.002EPSS

2006-01-04 12:03 AM
23
cve
cve

CVE-2006-1225

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

6.6AI Score

0.026EPSS

2006-03-14 07:06 PM
28
cve
cve

CVE-2006-1226

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

5.5AI Score

0.005EPSS

2006-03-14 07:06 PM
25
cve
cve

CVE-2006-1227

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.

6.5AI Score

0.005EPSS

2006-03-14 07:06 PM
29
cve
cve

CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

6.6AI Score

0.032EPSS

2006-03-14 07:06 PM
30
cve
cve

CVE-2006-2260

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

5.7AI Score

0.005EPSS

2006-05-09 10:02 AM
26
cve
cve

CVE-2006-2742

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

8AI Score

0.011EPSS

2006-06-01 10:02 AM
32
cve
cve

CVE-2006-2743

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

6.9AI Score

0.033EPSS

2006-06-01 10:02 AM
30
cve
cve

CVE-2006-2831

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

7.3AI Score

0.153EPSS

2006-06-06 12:02 AM
28
cve
cve

CVE-2006-2832

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

5.5AI Score

0.004EPSS

2006-06-06 12:02 AM
31
cve
cve

CVE-2006-2833

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

5.5AI Score

0.008EPSS

2006-06-06 12:02 AM
31
cve
cve

CVE-2006-3473

CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending spam messages, a different issue than CVE-2006-1225.

6.9AI Score

0.026EPSS

2006-07-10 08:05 PM
22
cve
cve

CVE-2006-3570

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.005EPSS

2006-07-13 01:05 AM
19
cve
cve

CVE-2006-4002

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

5.6AI Score

0.004EPSS

2006-08-07 07:04 PM
25
cve
cve

CVE-2006-4107

SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search.

8.7AI Score

0.006EPSS

2006-08-14 08:04 PM
20
cve
cve

CVE-2006-4108

SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

8.8AI Score

0.006EPSS

2006-08-14 08:04 PM
21
cve
cve

CVE-2006-4109

Cross-site scripting (XSS) vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6AI Score

0.005EPSS

2006-08-14 08:04 PM
23
cve
cve

CVE-2006-4120

Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6AI Score

0.025EPSS

2006-08-14 11:04 PM
21
cve
cve

CVE-2006-4355

Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6AI Score

0.005EPSS

2006-08-27 02:04 AM
24
cve
cve

CVE-2006-4356

SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

8.8AI Score

0.006EPSS

2006-08-27 02:04 AM
19
cve
cve

CVE-2006-4360

Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.

5.5AI Score

0.002EPSS

2006-08-27 02:04 AM
22
cve
cve

CVE-2006-4646

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module before pathauto_node.inc 1.14.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6AI Score

0.01EPSS

2006-09-08 09:04 PM
28
cve
cve

CVE-2006-4717

The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentication requirements and spoof identities of arbitrary users via unspecified vectors.

7AI Score

0.032EPSS

2006-09-12 04:07 PM
22
cve
cve

CVE-2006-4821

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.9AI Score

0.005EPSS

2006-09-15 10:07 PM
16
cve
cve

CVE-2006-4947

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "lack of validation on output."

5.9AI Score

0.01EPSS

2006-09-23 01:07 AM
17
cve
cve

CVE-2006-4949

Cross-site scripting (XSS) vulnerability in the Drupal 4.6 Site Profile Directory (profile_pages.module) before 1.1.2.1 and the Drupal 4.7 Site Profile Directory (profile_pages.module) before 1.2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "...

6AI Score

0.007EPSS

2006-09-23 01:07 AM
27
cve
cve

CVE-2006-5475

Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

5.7AI Score

0.027EPSS

2006-10-24 08:07 PM
19
cve
cve

CVE-2006-5476

Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.

7AI Score

0.018EPSS

2006-10-24 08:07 PM
26
cve
cve

CVE-2006-5477

Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.

6.5AI Score

0.012EPSS

2006-10-24 08:07 PM
21
cve
cve

CVE-2006-5608

SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "parameters from URLs."

8.7AI Score

0.005EPSS

2006-10-30 11:07 PM
18
cve
cve

CVE-2006-6386

Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote attackers to inject arbitrary web script or HTML via the motivation field in the CVS application page, which is not passe...

6AI Score

0.011EPSS

2006-12-08 01:28 AM
16
cve
cve

CVE-2006-6528

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.

7.3AI Score

0.012EPSS

2006-12-14 01:28 AM
21
cve
cve

CVE-2006-6529

The Chatroom Module before 4.7.x.-1.0 for Drupal displays private messages in a chatroom's last messages overview, which allows remote attackers to obtain sensitive information by reading the overview.

6.5AI Score

0.004EPSS

2022-10-03 04:21 PM
24
cve
cve

CVE-2006-6530

SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

8.8AI Score

0.003EPSS

2006-12-14 01:28 AM
18
cve
cve

CVE-2006-6531

Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.

6.2AI Score

0.005EPSS

2006-12-14 01:28 AM
17
cve
cve

CVE-2006-6646

Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, which do not use the check_plain function.

6.1AI Score

0.005EPSS

2006-12-20 02:28 AM
27
cve
cve

CVE-2006-6647

Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third party information.

6AI Score

0.005EPSS

2006-12-20 02:28 AM
18
cve
cve

CVE-2006-7109

Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a filename with a double extension such as .php.gif.

6.7AI Score

0.003EPSS

2007-03-05 08:19 PM
29
cve
cve

CVE-2006-7110

Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary files via ".." sequences.

6.7AI Score

0.003EPSS

2007-03-05 08:19 PM
16
cve
cve

CVE-2007-0124

Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.

6.2AI Score

0.014EPSS

2007-01-09 02:28 AM
23
cve
cve

CVE-2007-0136

Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information...

5.7AI Score

0.006EPSS

2007-01-09 11:28 AM
24
6
cve
cve

CVE-2007-0505

Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.

7.3AI Score

0.025EPSS

2007-01-26 12:28 AM
22
Total number of security vulnerabilities411