Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2015-7875
Disclosure Date: August 07, 2017 (last updated November 26, 2024)
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.
0
Attacker Value
Unknown
CVE-2015-6665
Disclosure Date: August 24, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
0
Attacker Value
Unknown
CVE-2015-4398
Disclosure Date: June 16, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
0
Attacker Value
Unknown
CVE-2015-4375
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.
0
Attacker Value
Unknown
CVE-2013-1925
Disclosure Date: July 16, 2013 (last updated October 05, 2023)
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.
0
Attacker Value
Unknown
CVE-2012-5559
Disclosure Date: December 03, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.
0
Attacker Value
Unknown
CVE-2012-2082
Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.
0
Attacker Value
Unknown
CVE-2010-2010
Disclosure Date: May 21, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.
0
Attacker Value
Unknown
CVE-2010-1546
Disclosure Date: May 21, 2010 (last updated October 04, 2023)
Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with "administer page manager" privileges, to execute arbitrary PHP code via input to a text area, related to (1) the page_manager_page_import_subtask_validate function in page_manager/plugins/tasks/page.admin.inc and (2) the page_manager_handler_import_validate function in page_manager/page_manager.admin.inc.
0
Attacker Value
Unknown
CVE-2010-1548
Disclosure Date: May 21, 2010 (last updated October 04, 2023)
The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.
0