Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2006-4646
Disclosure Date: September 08, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module before pathauto_node.inc 1.14.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-4002
Disclosure Date: August 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-3570
Disclosure Date: July 13, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-2831
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
0
Attacker Value
Unknown
CVE-2006-2833
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.
0
Attacker Value
Unknown
CVE-2006-2832
Disclosure Date: June 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.
0
Attacker Value
Unknown
CVE-2006-2742
Disclosure Date: June 01, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
0
Attacker Value
Unknown
CVE-2006-2743
Disclosure Date: June 01, 2006 (last updated October 04, 2023)
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
0
Attacker Value
Unknown
CVE-2006-2260
Disclosure Date: May 09, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2006-1225
Disclosure Date: March 14, 2006 (last updated February 22, 2025)
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
0