Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown

CVE-2015-5504

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-4354

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Integration module before 6.x-1.8 and 7.x before 7.x-2.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-4384

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ubercart Webform Checkout Pane module 6.x-3.x before 6.x-3.10 and 7.x-3.x before 7.x-3.11 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-4358

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Ubercart Discount Coupons module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.
0
Attacker Value
Unknown

CVE-2015-3342

Disclosure Date: April 21, 2015 (last updated October 05, 2023)
Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter.
0
Attacker Value
Unknown

CVE-2014-9026

Disclosure Date: November 20, 2014 (last updated October 05, 2023)
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-2301

Disclosure Date: November 16, 2014 (last updated October 05, 2023)
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-7302

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.
0
Attacker Value
Unknown

CVE-2013-0322

Disclosure Date: March 27, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.
0
Attacker Value
Unknown

CVE-2012-5802

Disclosure Date: November 04, 2012 (last updated October 05, 2023)
The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0