Lucene search

K

Drupal Security Vulnerabilities

cve
cve

CVE-2007-0506

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.

6.1AI Score

0.005EPSS

2007-01-26 12:28 AM
17
cve
cve

CVE-2007-0507

SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.

8AI Score

0.003EPSS

2007-01-26 12:28 AM
24
cve
cve

CVE-2007-0534

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain "fields on project nod...

5.5AI Score

0.006EPSS

2007-01-26 01:28 AM
23
cve
cve

CVE-2007-0626

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form va...

7.5AI Score

0.034EPSS

2007-01-31 06:28 PM
30
6
cve
cve

CVE-2007-0658

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

6.8AI Score

0.095EPSS

2007-02-01 10:28 PM
36
cve
cve

CVE-2007-1033

Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions via a crafted URL.

6.5AI Score

0.012EPSS

2007-02-21 11:28 AM
29
cve
cve

CVE-2007-1035

Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors.

6.8AI Score

0.025EPSS

2007-02-21 11:28 AM
35
cve
cve

CVE-2007-1360

Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' profiles via unspecified URL parameters.

6.3AI Score

0.005EPSS

2007-03-08 10:19 PM
17
cve
cve

CVE-2007-1368

The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.

6.2AI Score

0.003EPSS

2007-03-09 10:19 PM
22
cve
cve

CVE-2007-2159

Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-, and before 4.7.x-1.2 in the 4.7.x-1. series, for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct display of data from the datab...

5.8AI Score

0.003EPSS

2007-04-22 07:19 PM
27
cve
cve

CVE-2007-2160

Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-, and before 4.7.x-1.2 in the 4.7.x-1. series, for Drupal allow remote attackers to perform unauthorized actions as an arbitrary user, a related issue to CVE-2006-5476.

7.2AI Score

0.018EPSS

2007-04-22 07:19 PM
28
cve
cve

CVE-2007-3689

The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.

6.7AI Score

0.011EPSS

2007-07-11 05:30 PM
20
cve
cve

CVE-2007-3690

The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.

6.7AI Score

0.011EPSS

2007-07-11 05:30 PM
21
cve
cve

CVE-2007-3817

Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the u...

5.7AI Score

0.004EPSS

2007-07-17 01:30 AM
24
cve
cve

CVE-2007-3818

Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission to inject arbitrary JavaScript and gain privileges via "the message displayed above the default user login block."

5.7AI Score

0.001EPSS

2007-07-17 01:30 AM
24
cve
cve

CVE-2007-4063

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.

6.8AI Score

0.01EPSS

2007-07-30 05:30 PM
19
cve
cve

CVE-2007-4064

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script o...

5.4AI Score

0.006EPSS

2007-07-30 05:30 PM
22
cve
cve

CVE-2007-4363

Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the au...

5.8AI Score

0.03EPSS

2007-08-15 07:17 PM
20
cve
cve

CVE-2007-4436

The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain proje...

6.2AI Score

0.008EPSS

2007-08-20 10:17 PM
20
cve
cve

CVE-2007-5228

Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module before 4.7.x-1.5, 4.7.x-2.x before 4.7.x-2.5, and 5.x-1.x before 5.x-1.1 for Drupal allows remote authenticated users with project create or edit permissions to inject arbitrary web scrip...

5.3AI Score

0.001EPSS

2007-10-05 11:17 PM
31
cve
cve

CVE-2007-5416

Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to th...

7.2AI Score

0.054EPSS

2007-10-12 09:17 PM
33
cve
cve

CVE-2007-5593

install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.

7.3AI Score

0.117EPSS

2007-10-19 11:17 PM
17
cve
cve

CVE-2007-5594

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

6.5AI Score

0.002EPSS

2007-10-19 11:17 PM
20
cve
cve

CVE-2007-5595

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

6.7AI Score

0.016EPSS

2007-10-19 11:17 PM
19
cve
cve

CVE-2007-5596

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

5.6AI Score

0.002EPSS

2007-10-19 11:17 PM
29
cve
cve

CVE-2007-5597

The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.

6.3AI Score

0.006EPSS

2007-10-19 11:17 PM
20
cve
cve

CVE-2007-5621

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a ...

5.5AI Score

0.001EPSS

2007-10-22 07:46 PM
28
cve
cve

CVE-2007-6298

Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

5.3AI Score

0.003EPSS

2007-12-10 06:46 PM
17
cve
cve

CVE-2007-6299

Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser ...

8.2AI Score

0.003EPSS

2007-12-10 06:46 PM
19
cve
cve

CVE-2007-6320

Feature 4.7.x-dev and 5.x-dev before 20071206, a Drupal module, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks.

6.8AI Score

0.001EPSS

2007-12-12 01:46 AM
26
cve
cve

CVE-2007-6752

Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit ...

7.3AI Score

0.005EPSS

2022-10-03 04:14 PM
29
cve
cve

CVE-2008-0264

Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node.

7.3AI Score

0.045EPSS

2008-01-15 08:00 PM
14
cve
cve

CVE-2008-0271

The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.

6.8AI Score

0.002EPSS

2008-01-15 08:00 PM
20
cve
cve

CVE-2008-0272

Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.

6.6AI Score

0.003EPSS

2008-01-15 08:00 PM
22
4
cve
cve

CVE-2008-0273

Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8...

5.5AI Score

0.004EPSS

2008-01-15 08:00 PM
29
4
cve
cve

CVE-2008-0274

Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.

5.6AI Score

0.003EPSS

2008-01-15 08:00 PM
19
cve
cve

CVE-2008-0275

The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content.

7AI Score

0.003EPSS

2008-01-15 08:00 PM
17
cve
cve

CVE-2008-0276

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

5.6AI Score

0.001EPSS

2008-01-15 08:00 PM
21
cve
cve

CVE-2008-0277

Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.

7.4AI Score

0.004EPSS

2008-01-15 08:00 PM
19
cve
cve

CVE-2008-0462

Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.003EPSS

2008-01-25 04:00 PM
19
cve
cve

CVE-2008-0463

Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving node properties.

5.7AI Score

0.003EPSS

2008-01-25 04:00 PM
23
cve
cve

CVE-2008-0568

Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker.

6.7AI Score

0.008EPSS

2008-02-05 02:00 AM
19
cve
cve

CVE-2008-0569

The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors.

7.5AI Score

0.02EPSS

2008-02-05 02:00 AM
17
cve
cve

CVE-2008-0570

The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.

6.9AI Score

0.002EPSS

2008-02-05 02:00 AM
21
cve
cve

CVE-2008-0571

The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and manipulate points.

6.8AI Score

0.002EPSS

2008-02-05 02:00 AM
18
cve
cve

CVE-2008-0576

Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authe...

5.3AI Score

0.002EPSS

2008-02-05 02:00 AM
22
cve
cve

CVE-2008-0577

The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal (1) does not restrict the extensions of attached files when the...

7.3AI Score

0.003EPSS

2008-02-05 02:00 AM
15
cve
cve

CVE-2008-0823

Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown attack vectors.

6.6AI Score

0.011EPSS

2008-02-19 08:44 PM
18
cve
cve

CVE-2008-1131

Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.

5.3AI Score

0.001EPSS

2022-10-03 04:13 PM
13
cve
cve

CVE-2008-1133

The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

5.8AI Score

0.001EPSS

2022-10-03 04:13 PM
19
Total number of security vulnerabilities411