Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Unknown
CVE-2021-41182
Disclosure Date: October 26, 2021 (last updated February 23, 2025)
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not accept the value of the `altField` option from untrusted sources.
0
Attacker Value
Unknown
CVE-2021-41183
Disclosure Date: October 26, 2021 (last updated February 23, 2025)
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.
0
Attacker Value
Unknown
CVE-2021-41184
Disclosure Date: October 26, 2021 (last updated February 23, 2025)
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.
0
Attacker Value
Unknown
CVE-2015-2750
Disclosure Date: September 13, 2017 (last updated November 26, 2024)
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
0
Attacker Value
Unknown
CVE-2015-2749
Disclosure Date: September 13, 2017 (last updated November 26, 2024)
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
0
Attacker Value
Unknown
CVE-2016-3167
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.
0
Attacker Value
Unknown
CVE-2016-3164
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.
0
Attacker Value
Unknown
CVE-2016-3166
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.
0
Attacker Value
Unknown
CVE-2016-3163
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
0
Attacker Value
Unknown
CVE-2016-3165
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.
0