Show filters
488 Total Results
Displaying 421-430 of 488
Sort by:
Attacker Value
Unknown
CVE-2007-4064
Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
0
Attacker Value
Unknown
CVE-2007-4063
Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.
0
Attacker Value
Unknown
CVE-2007-3818
Disclosure Date: July 17, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission to inject arbitrary JavaScript and gain privileges via "the message displayed above the default user login block."
0
Attacker Value
Unknown
CVE-2007-3817
Disclosure Date: July 17, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the username by removing certain characters, so this might not be a vulnerability on default installations.
0
Attacker Value
Unknown
CVE-2007-3690
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.
0
Attacker Value
Unknown
CVE-2007-3689
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.
0
Attacker Value
Unknown
CVE-2007-2159
Disclosure Date: April 22, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct display of data from the database and (2) other portions of the user interface.
0
Attacker Value
Unknown
CVE-2007-2160
Disclosure Date: April 22, 2007 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to perform unauthorized actions as an arbitrary user, a related issue to CVE-2006-5476.
0
Attacker Value
Unknown
CVE-2007-1368
Disclosure Date: March 09, 2007 (last updated October 04, 2023)
The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node identifier.
0
Attacker Value
Unknown
CVE-2007-1360
Disclosure Date: March 08, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' profiles via unspecified URL parameters.
0