|
171
|
-
5.0
|
MEDIUM
|
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote att…
|
CWE-287
Improper Authentication
|
CVE-2010-3091
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 10:18
2010-09-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
-
2.1
|
LOW
|
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action descrip…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3094
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 10:18
2010-09-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
-
3.5
|
LOW
|
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3093
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 10:18
2010-09-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
-
5.5
|
MEDIUM
|
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3092
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2024-11-21 10:18
2010-09-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4371
|
cpe:2.3:a:drupal:drupal:6.15:* cpe:2.3:a:drupal:drupal:6.14:*
|
|
|
|
|
2026-04-23 09:35
2009-12-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inje…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4370
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2026-04-23 09:35
2009-12-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
-
3.5
|
LOW
|
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote a…
|
CWE-79
Cross-site Scripting
|
CVE-2009-4369
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2026-04-23 09:35
2009-12-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
-
10.0
|
HIGH
|
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-3352
|
cpe:2.3:a:drupal:drupal:*:*
|
5.0
|
|
|
7.0
|
2026-04-23 09:35
2009-09-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
-
4.3
|
MEDIUM
|
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read…
|
CWE-255
Credentials Management
|
CVE-2009-2374
|
cpe:2.3:a:drupal:drupal:*:*
|
5.0 6.0
|
|
|
5.19 6.13
|
2026-04-23 09:35
2009-07-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2009-2373
|
cpe:2.3:a:drupal:drupal:6.9:* cpe:2.3:a:drupal:drupal:6.8:* cpe:2.3:a:drupal:drupal:6.7:* cpe:2.3:a:drupal:dru…
|
|
|
|
|
2026-04-23 09:35
2009-07-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|