|
161
|
-
4.0
|
MEDIUM
|
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1590
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 10:37
2012-10-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
-
3.5
|
LOW
|
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain r…
|
CWE-399
Resource Management Errors
|
CVE-2012-1588
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 10:37
2012-10-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
-
7.5
|
HIGH
|
SQL injection vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-2306
|
cpe:2.3:a:drupal:drupal:-:*
|
|
|
|
|
2024-11-21 10:38
2012-07-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
-
5.0
|
MEDIUM
|
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installati…
|
CWE-200
Information Exposure
|
CVE-2012-2922
|
cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal:drupal:7.7:* cpe:2.3:a:drupal:dru…
|
|
7.14
|
|
|
2024-11-21 10:39
2012-05-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
-
5.8
|
MEDIUM
|
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destina…
|
CWE-20
Improper Input Validation
|
CVE-2012-1589
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
|
|
|
2024-11-21 10:37
2012-05-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
-
6.8
|
MEDIUM
|
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout …
|
CWE-352
Origin Validation Error
|
CVE-2007-6752
|
cpe:2.3:a:drupal:drupal:7.x-dev:* cpe:2.3:a:drupal:drupal:7.9:* cpe:2.3:a:drupal:drupal:7.8:* cpe:2.3:a:drupal…
|
|
7.12
|
|
|
2024-11-21 09:40
2012-03-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
-
5.0
|
MEDIUM
|
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/…
|
CWE-200
Information Exposure
|
CVE-2011-3730
|
cpe:2.3:a:drupal:drupal:7.0:*
|
|
|
|
|
2024-11-21 10:31
2011-09-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
-
7.5
|
HIGH
|
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-2687
|
cpe:2.3:a:drupal:drupal:7.2:* cpe:2.3:a:drupal:drupal:7.1:* cpe:2.3:a:drupal:drupal:7.0:rc4 cpe:2.3:a:drupal:d…
|
|
|
|
|
2024-11-21 10:28
2011-07-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
-
5.0
|
MEDIUM
|
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attacker…
|
CWE-287
Improper Authentication
|
CVE-2010-3686
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 10:19
2010-09-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
-
5.0
|
MEDIUM
|
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which all…
|
CWE-287
Improper Authentication
|
CVE-2010-3685
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 10:19
2010-09-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|