Show filters
140 Total Results
Displaying 111-120 of 140
Sort by:
Attacker Value
Unknown
CVE-2015-5509
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5490
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intended filters and obtain access to hidden content via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-3379
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-3378
Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to the break lock page for edited views.
0
Attacker Value
Unknown
CVE-2014-7683
Disclosure Date: October 21, 2014 (last updated October 05, 2023)
The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2013-3252
Disclosure Date: April 10, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-1887
Disclosure Date: March 27, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via certain view configuration fields.
0
Attacker Value
Unknown
CVE-2013-0321
Disclosure Date: March 27, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.
0
Attacker Value
Unknown
CVE-2013-2501
Disclosure Date: March 22, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.
0
Attacker Value
Unknown
CVE-2010-5277
Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.
0