Show filters
488 Total Results
Displaying 211-220 of 488
Sort by:
Attacker Value
Unknown
CVE-2014-8296
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3704
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
0
Attacker Value
Unknown
CVE-2014-8765
Disclosure Date: October 14, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and return the results to the PIFR_Server test results page or (2) remote authenticated users with the "manage PIFR environments" permission to inject arbitrary web script or HTML via vectors involving a PIFR_Server administrative page.
0
Attacker Value
Unknown
CVE-2014-8744
Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrary web script or HTML via an image title.
0
Attacker Value
Unknown
CVE-2014-8748
Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.
0
Attacker Value
Unknown
CVE-2014-8743
Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.
0
Attacker Value
Unknown
CVE-2014-8747
Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content creation and activity stream messages.
0
Attacker Value
Unknown
CVE-2014-8745
Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.
0
Attacker Value
Unknown
CVE-2014-8746
Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
0
Attacker Value
Unknown
CVE-2014-8077
Disclosure Date: October 09, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to font family CSS property.
0