Show filters
488 Total Results
Displaying 341-350 of 488
Sort by:
Attacker Value
Unknown

CVE-2008-4793

Disclosure Date: October 29, 2008 (last updated October 04, 2023)
The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors related to contributed modules.
0
Attacker Value
Unknown

CVE-2008-4710

Disclosure Date: October 23, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the stock quotes page in Stock 6.x before 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4633

Disclosure Date: October 21, 2008 (last updated October 04, 2023)
SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."
0
Attacker Value
Unknown

CVE-2008-4597

Disclosure Date: October 17, 2008 (last updated October 04, 2023)
Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-4596

Disclosure Date: October 17, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in generated pages.
0
Attacker Value
Unknown

CVE-2008-4598

Disclosure Date: October 17, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Shindig-Integrator 5.x, a module for Drupal, has unspecified impact and remote attack vectors related to "numerous flaws" that are not related to XSS or access control, a different vulnerability than CVE-2008-4596 and CVE-2008-4597.
0
Attacker Value
Unknown

CVE-2008-4531

Disclosure Date: October 09, 2008 (last updated October 04, 2023)
SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to queries. NOTE: this might be the same issue as CVE-2008-4338.
0
Attacker Value
Unknown

CVE-2008-4530

Disclosure Date: October 09, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote authenticated users with permissions to inject arbitrary web script or HTML via unspecified vectors related to posting of answers.
0
Attacker Value
Unknown

CVE-2008-4153

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2008-4152

Disclosure Date: September 24, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via a node title.
0