Show filters
488 Total Results
Displaying 311-320 of 488
Sort by:
Attacker Value
Unknown

CVE-2009-1069

Disclosure Date: March 26, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.
0
Attacker Value
Unknown

CVE-2009-1047

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vectors involving outbound HTML e-mail.
0
Attacker Value
Unknown

CVE-2009-1034

Disclosure Date: March 20, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.
0
Attacker Value
Unknown

CVE-2009-1037

Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to send unlimited spam messages via unknown vectors related to the flood control API.
0
Attacker Value
Unknown

CVE-2009-1036

Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for content via unspecified aspects of the URI.
0
Attacker Value
Unknown

CVE-2009-0818

Disclosure Date: March 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the taxonomy_theme_admin_table_builder function (taxonomy_theme_admin.inc) in Taxonomy Theme module before 5.x-1.2, a module for Drupal, allows remote authenticated users with the "administer taxonomy" permission, or the ability to create pages when tagging is enabled, to inject arbitrary web script or HTML via the Vocabulary name (name parameter) to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-0817

Disclosure Date: March 05, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.
0
Attacker Value
Unknown

CVE-2008-6384

Disclosure Date: March 02, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack the authentication of administrators.
0
Attacker Value
Unknown

CVE-2008-6383

Disclosure Date: March 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-6276

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.
0