|
131
|
-
6.8
|
MEDIUM
|
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5267
|
cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal:drupal:7.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 11:11
2014-09-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
-
5.0
|
MEDIUM
|
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote atta…
|
CWE-399
Resource Management Errors
|
CVE-2014-5266
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 11:11
2014-08-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
-
5.0
|
MEDIUM
|
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion,…
|
CWE-399
Resource Management Errors
|
CVE-2014-5265
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 11:11
2014-08-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled t…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5022
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 11:11
2014-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
-
2.1
|
LOW
|
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5021
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 11:11
2014-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
-
4.9
|
MEDIUM
|
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5020
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 11:11
2014-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
-
5.0
|
MEDIUM
|
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration fil…
|
CWE-20
Improper Input Validation
|
CVE-2014-5019
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 11:11
2014-07-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
-
5.0
|
MEDIUM
|
Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input informati…
|
CWE-200
Information Exposure
|
CVE-2014-2983
|
cpe:2.3:a:drupal:drupal:*:*
|
7.0 6.0
|
|
|
7.27 6.31
|
2024-11-21 11:07
2014-04-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: thi…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1607
|
cpe:2.3:a:drupal:drupal:7.14:*
|
|
|
|
|
2024-11-21 11:04
2014-01-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
-
4.0
|
MEDIUM
|
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to ob…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1476
|
cpe:2.3:a:drupal:drupal:7.2:* cpe:2.3:a:drupal:drupal:7.24:* cpe:2.3:a:drupal:drupal:7.23:* cpe:2.3:a:drupal:d…
|
|
|
|
|
2024-11-21 11:04
2014-01-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|