Show filters
488 Total Results
Displaying 331-340 of 488
Sort by:
Attacker Value
Unknown

CVE-2008-6137

Disclosure Date: February 14, 2009 (last updated October 04, 2023)
EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-0575

Disclosure Date: February 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to node titles. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-6020

Disclosure Date: February 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK text fields."
0
Attacker Value
Unknown

CVE-2009-0382

Disclosure Date: February 02, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-5998

Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.
0
Attacker Value
Unknown

CVE-2008-5999

Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allows remote authenticated users, with create and edit permissions for posts, to inject arbitrary web script or HTML via unspecified vectors involving the ajax_checklist filter.
0
Attacker Value
Unknown

CVE-2008-4790

Disclosure Date: October 29, 2008 (last updated October 04, 2023)
The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-4789

Disclosure Date: October 29, 2008 (last updated October 04, 2023)
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."
0
Attacker Value
Unknown

CVE-2008-4791

Disclosure Date: October 29, 2008 (last updated October 04, 2023)
The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-4792

Disclosure Date: October 29, 2008 (last updated October 04, 2023)
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
0