Show filters
488 Total Results
Displaying 281-290 of 488
Sort by:
Attacker Value
Unknown

CVE-2010-3092

Disclosure Date: September 21, 2010 (last updated October 04, 2023)
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
0
Attacker Value
Unknown

CVE-2010-3022

Disclosure Date: August 16, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths in a URL.
0
Attacker Value
Unknown

CVE-2009-4602

Disclosure Date: January 12, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-4371

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
0
Attacker Value
Unknown

CVE-2009-4370

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
0
Attacker Value
Unknown

CVE-2009-4369

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
0
Attacker Value
Unknown

CVE-2009-4066

Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.
0
Attacker Value
Unknown

CVE-2009-3479

Disclosure Date: September 30, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows remote attackers, with "create content displayed by the Bibliography module" permissions, to inject arbitrary web script or HTML via a title.
0
Attacker Value
Unknown

CVE-2009-3352

Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2009-3156

Disclosure Date: September 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field.
0