Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown
CVE-2007-1368
Disclosure Date: March 09, 2007 (last updated October 04, 2023)
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.
0
Attacker Value
Unknown
CVE-2007-0841
Disclosure Date: February 08, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors. NOTE: the vector related to Drupal is covered by CVE-2007-0626. These vulnerabilities might be associated with other CVE identifiers.
0
Attacker Value
Unknown
CVE-2007-0658
Disclosure Date: February 01, 2007 (last updated October 04, 2023)
The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.
0
Attacker Value
Unknown
CVE-2007-0124
Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
0
Attacker Value
Unknown
CVE-2006-6646
Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, which do not use the check_plain function.
0
Attacker Value
Unknown
CVE-2006-6647
Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-5475
Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
0
Attacker Value
Unknown
CVE-2006-5477
Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.
0
Attacker Value
Unknown
CVE-2006-5476
Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-4821
Disclosure Date: September 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0