Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown

CVE-2007-1368

Disclosure Date: March 09, 2007 (last updated October 04, 2023)
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.
0
Attacker Value
Unknown

CVE-2007-0841

Disclosure Date: February 08, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in vbDrupal before 4.7.6.0 have unknown impact and remote attack vectors. NOTE: the vector related to Drupal is covered by CVE-2007-0626. These vulnerabilities might be associated with other CVE identifiers.
0
Attacker Value
Unknown

CVE-2007-0658

Disclosure Date: February 01, 2007 (last updated October 04, 2023)
The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.
0
Attacker Value
Unknown

CVE-2007-0124

Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
0
Attacker Value
Unknown

CVE-2006-6646

Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, which do not use the check_plain function.
0
Attacker Value
Unknown

CVE-2006-6647

Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-5475

Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
0
Attacker Value
Unknown

CVE-2006-5477

Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.
0
Attacker Value
Unknown

CVE-2006-5476

Disclosure Date: October 24, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-4821

Disclosure Date: September 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0