|
241
|
-
4.3
|
MEDIUM
|
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and value…
|
NVD-CWE-Other
|
CVE-2005-3973
|
cpe:2.3:a:drupal:drupal:4.6.3:* cpe:2.3:a:drupal:drupal:4.6.2:* cpe:2.3:a:drupal:drupal:4.6.1:* cpe:2.3:a:drup…
|
|
|
|
|
2018-10-20 00:39
2005-12-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
-
6.4
|
MEDIUM
|
Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.
|
NVD-CWE-Other
|
CVE-2005-3974
|
cpe:2.3:a:drupal:drupal:4.6:* cpe:2.3:a:drupal:drupal:4.6.3:* cpe:2.3:a:drupal:drupal:4.6.2:* cpe:2.3:a:drupal…
|
|
|
|
|
2018-10-20 00:39
2005-12-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
-
4.0
|
MEDIUM
|
Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPE…
|
NVD-CWE-Other
|
CVE-2005-3975
|
cpe:2.3:a:drupal:drupal:4.6.3:* cpe:2.3:a:drupal:drupal:4.6.2:* cpe:2.3:a:drupal:drupal:4.6.1:* cpe:2.3:a:drup…
|
|
|
|
|
2018-10-20 00:39
2005-12-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
-
5.0
|
MEDIUM
|
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.
|
NVD-CWE-Other
|
CVE-2005-2106
|
cpe:2.3:a:drupal:drupal:4.6.1:* cpe:2.3:a:drupal:drupal:4.6.0:* cpe:2.3:a:drupal:drupal:4.5.3:* cpe:2.3:a:drup…
|
|
|
|
|
2016-10-18 12:24
2005-07-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
-
7.5
|
HIGH
|
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2…
|
CWE-94
Code Injection
|
CVE-2005-1921
|
cpe:2.3:a:drupal:drupal:*:*
|
4.6.0
|
|
|
4.6.2 4.5.4
|
2024-02-15 00:41
2005-07-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
-
7.5
|
HIGH
|
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not impl…
|
NVD-CWE-Other
|
CVE-2005-1871
|
cpe:2.3:a:drupal:drupal:4.6.0:* cpe:2.3:a:drupal:drupal:4.5.2:* cpe:2.3:a:drupal:drupal:4.5.1:* cpe:2.3:a:drup…
|
|
|
|
|
2016-10-18 12:23
2005-06-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
|
NVD-CWE-Other
|
CVE-2005-0682
|
cpe:2.3:a:drupal:drupal:4.5.1:* cpe:2.3:a:drupal:drupal:4.5.0:* cpe:2.3:a:drupal:drupal:4.4.2:* cpe:2.3:a:drup…
|
|
|
|
|
2008-09-6 05:47
2005-05-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
-
4.3
|
MEDIUM
|
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
|
NVD-CWE-Other
|
CVE-2002-1806
|
cpe:2.3:a:drupal:drupal:4.0.0:*
|
|
|
|
|
2008-09-6 05:31
2002-12-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|