Show filters
488 Total Results
Displaying 281-290 of 488
Sort by:
Attacker Value
Unknown
CVE-2010-3092
Disclosure Date: September 21, 2010 (last updated October 04, 2023)
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
0
Attacker Value
Unknown
CVE-2010-3022
Disclosure Date: August 16, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths in a URL.
0
Attacker Value
Unknown
CVE-2009-4602
Disclosure Date: January 12, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4371
Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
0
Attacker Value
Unknown
CVE-2009-4370
Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
0
Attacker Value
Unknown
CVE-2009-4369
Disclosure Date: December 21, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
0
Attacker Value
Unknown
CVE-2009-4066
Disclosure Date: November 24, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.
0
Attacker Value
Unknown
CVE-2009-3479
Disclosure Date: September 30, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows remote attackers, with "create content displayed by the Bibliography module" permissions, to inject arbitrary web script or HTML via a title.
0
Attacker Value
Unknown
CVE-2009-3352
Disclosure Date: September 24, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2009-3156
Disclosure Date: September 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field.
0