Show filters
488 Total Results
Displaying 121-130 of 488
Sort by:
Attacker Value
Unknown
CVE-2020-9281
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
0
Attacker Value
Unknown
CVE-2013-4226
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
0
Attacker Value
Unknown
CVE-2011-2715
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
0
Attacker Value
Unknown
CVE-2011-2714
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
0
Attacker Value
Unknown
CVE-2019-19826
Disclosure Date: December 16, 2019 (last updated November 27, 2024)
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.
0
Attacker Value
Unknown
CVE-2011-3373
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.
0
Attacker Value
Unknown
CVE-2012-2079
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
0
Attacker Value
Unknown
CVE-2012-2078
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.
0
Attacker Value
Unknown
CVE-2012-1637
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
0
Attacker Value
Unknown
CVE-2011-2726
Disclosure Date: November 15, 2019 (last updated November 27, 2024)
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
0