Show filters
488 Total Results
Displaying 221-230 of 488
Sort by:
Attacker Value
Unknown
CVE-2014-8079
Disclosure Date: October 09, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to header background setting.
0
Attacker Value
Unknown
CVE-2014-8075
Disclosure Date: October 09, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.
0
Attacker Value
Unknown
CVE-2014-8076
Disclosure Date: October 09, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright information.
0
Attacker Value
Unknown
CVE-2014-8078
Disclosure Date: October 09, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes.
0
Attacker Value
Unknown
CVE-2014-7980
Disclosure Date: October 08, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.
0
Attacker Value
Unknown
CVE-2014-7979
Disclosure Date: October 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
0
Attacker Value
Unknown
CVE-2014-7978
Disclosure Date: October 08, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.
0
Attacker Value
Unknown
CVE-2014-7870
Disclosure Date: October 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom search" permission to inject arbitrary web script or HTML via the "Label text" field to admin/config/search/custom_search/results.
0
Attacker Value
Unknown
CVE-2014-7869
Disclosure Date: October 06, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-5267
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
0