Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2013-4225
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
0
Attacker Value
Unknown
CVE-2015-4394
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4344
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.
0
Attacker Value
Unknown
CVE-2015-4393
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.
0
Attacker Value
Unknown
CVE-2015-4345
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-2215
Disclosure Date: March 05, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.
0
Attacker Value
Unknown
CVE-2014-9335
Disclosure Date: December 19, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the DandyID Services plugin 1.5.9 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) email_address or (2) sidebarTitle parameter in the dandyid-services.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown
CVE-2014-9153
Disclosure Date: December 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response.
0
Attacker Value
Unknown
CVE-2014-9151
Disclosure Date: December 01, 2014 (last updated October 05, 2023)
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
0
Attacker Value
Unknown
CVE-2014-9152
Disclosure Date: December 01, 2014 (last updated October 05, 2023)
The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
0