Lucene search

K

Drupal Security Vulnerabilities

cve
cve

CVE-2008-1428

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-beta7 module for Drupal allow remote attackers to inject arbitrary web script or HTML via a text attribute value for a product.

5.6AI Score

0.002EPSS

2008-03-20 06:44 PM
17
cve
cve

CVE-2008-1729

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows re...

6.1AI Score

0.005EPSS

2008-04-11 07:05 PM
21
cve
cve

CVE-2008-1794

Multiple cross-site scripting (XSS) vulnerabilities in the Webform Drupal module 5.x before 5.x-1.10, 5.x-2.x before 5.x-2.0-beta3, and 6.x before 6.x-1.0-beta3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.003EPSS

2008-04-15 05:05 PM
15
cve
cve

CVE-2008-1916

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text fields intended for the (1) address and (2) order information, which are later displayed on the order view page and uns...

5.8AI Score

0.002EPSS

2008-04-23 01:05 PM
19
cve
cve

CVE-2008-1978

Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before 5.x-1.0 rc3 module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via node titles related to unspecified product features, a different vector than CVE-2008-1428.

5.2AI Score

0.002EPSS

2008-04-27 08:05 PM
16
cve
cve

CVE-2008-1980

Cross-site scripting (XSS) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.002EPSS

2008-04-27 08:05 PM
18
cve
cve

CVE-2008-2771

The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass restrictions and modify the node hierarchy via unspecified attack vectors.

6.8AI Score

0.004EPSS

2008-06-18 10:41 PM
16
cve
cve

CVE-2008-2772

The Magic Tabs module 5.x before 5.x-1.1 for Drupal allows remote attackers to execute arbitrary PHP code via unspecified URL arguments, possibly related to a missing "whitelist of callbacks."

7.8AI Score

0.008EPSS

2008-06-18 10:41 PM
17
cve
cve

CVE-2008-2773

Cross-site scripting (XSS) vulnerability in the Taxonomy Image module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.002EPSS

2008-06-18 10:41 PM
24
cve
cve

CVE-2008-2849

Cross-site scripting (XSS) vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote authenticated users, with create post permissions, to inject arbitrary web script or HTML via unspecified vectors.

5.3AI Score

0.001EPSS

2008-06-25 12:36 PM
20
cve
cve

CVE-2008-2850

SQL injection vulnerability in the TrailScout module 5.x before 5.x-1.4 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified cookies, related to improper use of the Drupal database API.

8.4AI Score

0.001EPSS

2008-06-25 12:36 PM
19
cve
cve

CVE-2008-2998

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.8AI Score

0.002EPSS

2008-07-03 06:41 PM
25
cve
cve

CVE-2008-2999

Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

8.6AI Score

0.001EPSS

2008-07-03 06:41 PM
19
cve
cve

CVE-2008-3000

The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intended restrictions.

6.8AI Score

0.006EPSS

2008-07-03 06:41 PM
18
cve
cve

CVE-2008-3001

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.

7.4AI Score

0.04EPSS

2008-07-03 06:41 PM
14
cve
cve

CVE-2008-3091

Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to inject arbitrary web script or HTML via unspecified vectors.

5.3AI Score

0.001EPSS

2008-07-09 07:33 PM
19
cve
cve

CVE-2008-3092

SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors.

8AI Score

0.001EPSS

2008-07-09 07:33 PM
14
cve
cve

CVE-2008-3095

Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors.

5.3AI Score

0.001EPSS

2008-07-09 07:33 PM
23
cve
cve

CVE-2008-3096

The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, which might allow remote attackers to gain privileges.

7.2AI Score

0.002EPSS

2008-07-09 07:33 PM
14
cve
cve

CVE-2008-3097

Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.

5.4AI Score

0.001EPSS

2008-07-09 07:33 PM
21
cve
cve

CVE-2008-3218

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.

5.5AI Score

0.002EPSS

2008-07-18 04:41 PM
25
cve
cve

CVE-2008-3219

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

5.3AI Score

0.003EPSS

2008-07-18 04:41 PM
23
cve
cve

CVE-2008-3220

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

6.5AI Score

0.003EPSS

2008-07-18 04:41 PM
21
cve
cve

CVE-2008-3221

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

6.4AI Score

0.003EPSS

2008-07-18 04:41 PM
20
2
cve
cve

CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

6.2AI Score

0.004EPSS

2008-07-18 04:41 PM
19
4
cve
cve

CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

8AI Score

0.004EPSS

2008-07-18 04:41 PM
23
2
cve
cve

CVE-2008-3500

Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.

5.3AI Score

0.003EPSS

2008-08-06 06:41 PM
23
cve
cve

CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

6.1AI Score

0.002EPSS

2008-09-23 03:25 PM
22
cve
cve

CVE-2008-3740

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.4AI Score

0.003EPSS

2008-08-27 03:21 PM
20
cve
cve

CVE-2008-3741

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

5.2AI Score

0.001EPSS

2008-08-27 03:21 PM
21
cve
cve

CVE-2008-3742

Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.

7AI Score

0.014EPSS

2008-08-27 03:21 PM
27
cve
cve

CVE-2008-3743

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.

6.8AI Score

0.003EPSS

2008-08-27 03:21 PM
16
cve
cve

CVE-2008-3744

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

6.9AI Score

0.003EPSS

2008-08-27 03:21 PM
24
cve
cve

CVE-2008-3745

The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.

6AI Score

0.002EPSS

2008-08-27 03:21 PM
21
cve
cve

CVE-2008-4147

Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an attached file that has a modified Content-Type.

5.8AI Score

0.003EPSS

2008-09-24 05:41 AM
18
cve
cve

CVE-2008-4148

SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API.

8.4AI Score

0.002EPSS

2008-09-24 05:41 AM
15
cve
cve

CVE-2008-4149

Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link page header" field.

5.3AI Score

0.003EPSS

2008-09-24 05:41 AM
23
cve
cve

CVE-2008-4152

Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via a node title.

5.3AI Score

0.001EPSS

2008-09-24 05:41 AM
16
cve
cve

CVE-2008-4153

The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive information.

6.5AI Score

0.004EPSS

2008-09-24 05:41 AM
20
cve
cve

CVE-2008-4530

Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote authenticated users with permissions to inject arbitrary web script or HTML via unspecified vectors related to posting of answers.

5.3AI Score

0.001EPSS

2008-10-09 06:14 PM
21
cve
cve

CVE-2008-4531

SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to queries. NOTE: this might be the same issue as CVE-2008-4338.

8.3AI Score

0.002EPSS

2008-10-09 06:14 PM
20
cve
cve

CVE-2008-4596

Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in generated pages.

5.3AI Score

0.002EPSS

2008-10-17 09:29 PM
22
cve
cve

CVE-2008-4597

Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via unspecified vectors.

6.9AI Score

0.005EPSS

2008-10-17 09:29 PM
20
cve
cve

CVE-2008-4598

Unspecified vulnerability in Shindig-Integrator 5.x, a module for Drupal, has unspecified impact and remote attack vectors related to "numerous flaws" that are not related to XSS or access control, a different vulnerability than CVE-2008-4596 and CVE-2008-4597.

6AI Score

0.005EPSS

2008-10-17 09:29 PM
24
cve
cve

CVE-2008-4633

SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."

7.9AI Score

0.001EPSS

2008-10-21 01:18 AM
19
cve
cve

CVE-2008-4710

Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

5.7AI Score

0.002EPSS

2008-10-23 05:17 PM
22
cve
cve

CVE-2008-4789

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

6.3AI Score

0.002EPSS

2008-10-29 03:31 PM
18
cve
cve

CVE-2008-4790

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

6.2AI Score

0.003EPSS

2008-10-29 03:31 PM
20
cve
cve

CVE-2008-4791

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.

6.2AI Score

0.002EPSS

2008-10-29 03:31 PM
27
cve
cve

CVE-2008-4792

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

6.2AI Score

0.002EPSS

2008-10-29 03:31 PM
23
Total number of security vulnerabilities411