Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2013-4225

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
Attacker Value
Unknown

CVE-2015-4394

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-4344

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.
0
Attacker Value
Unknown

CVE-2015-4393

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.
0
Attacker Value
Unknown

CVE-2015-4345

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-2215

Disclosure Date: March 05, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.
0
Attacker Value
Unknown

CVE-2014-9335

Disclosure Date: December 19, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the DandyID Services plugin 1.5.9 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) email_address or (2) sidebarTitle parameter in the dandyid-services.php page to wp-admin/options-general.php.
0
Attacker Value
Unknown

CVE-2014-9153

Disclosure Date: December 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response.
0
Attacker Value
Unknown

CVE-2014-9151

Disclosure Date: December 01, 2014 (last updated October 05, 2023)
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
0
Attacker Value
Unknown

CVE-2014-9152

Disclosure Date: December 01, 2014 (last updated October 05, 2023)
The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
0