Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2011-4113

Disclosure Date: February 17, 2012 (last updated October 04, 2023)
SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments."
0
Attacker Value
Unknown

CVE-2010-4521

Disclosure Date: December 23, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.
0
Attacker Value
Unknown

CVE-2010-4519

Disclosure Date: December 23, 2010 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.
0
Attacker Value
Unknown

CVE-2010-4520

Disclosure Date: December 23, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.
0
Attacker Value
Unknown

CVE-2009-2077

Disclosure Date: June 16, 2009 (last updated October 04, 2023)
Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in generated queries.
0
Attacker Value
Unknown

CVE-2009-2076

Disclosure Date: June 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is only exploitable by users with administer views permissions.
0