Show filters
488 Total Results
Displaying 131-140 of 488
Sort by:
Attacker Value
Unknown
CVE-2019-18856
Disclosure Date: November 11, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
0
Attacker Value
Unknown
CVE-2010-2472
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
0
Attacker Value
Unknown
CVE-2010-2473
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
0
Attacker Value
Unknown
CVE-2010-2250
Disclosure Date: November 07, 2019 (last updated November 27, 2024)
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
0
Attacker Value
Unknown
CVE-2010-2471
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Drupal versions 5.x and 6.x has open redirection
0
Attacker Value
Unknown
CVE-2019-11876
Disclosure Date: May 24, 2019 (last updated November 27, 2024)
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.
0
Attacker Value
Unknown
CVE-2019-10909
Disclosure Date: May 16, 2019 (last updated November 27, 2024)
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
0
Attacker Value
Unknown
CVE-2019-10911
Disclosure Date: May 16, 2019 (last updated November 27, 2024)
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
0
Attacker Value
Unknown
CVE-2019-10910
Disclosure Date: May 16, 2019 (last updated November 27, 2024)
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
0
Attacker Value
Unknown
CVE-2019-11831
Disclosure Date: May 09, 2019 (last updated November 08, 2023)
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
0