Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Unknown

CVE-2020-11023

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Attacker Value
Unknown

CVE-2015-2750

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
0
Attacker Value
Unknown

CVE-2015-2749

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
0
Attacker Value
Unknown

CVE-2016-3167

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.
0
Attacker Value
Unknown

CVE-2016-3164

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
0
Attacker Value
Unknown

CVE-2016-3166

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
0
Attacker Value
Unknown

CVE-2016-3163

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
0
Attacker Value
Unknown

CVE-2016-3165

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.
0
Attacker Value
Unknown

CVE-2016-3168

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."
0
Attacker Value
Unknown

CVE-2016-3171

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.
0