258101
|
- |
|
yabsoft
|
mega_file_hosting_script
|
Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote attackers to inject arbitrary web script or HTML via the moudi param…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3647
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258102
|
- |
|
apsivam
|
service_links
|
Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2009-3648
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258103
|
- |
|
david_strauss
|
dex
|
Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3650
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258104
|
- |
|
mikeryan
|
browscap
|
Cross-site scripting (XSS) vulnerability in the "Monitor browsers' feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2009-3651
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258105
|
- |
|
apsivam
|
service_links
|
Per: http://www.madirish.net/?article=251
Patch
Applying the following patch mitigates these threats.
--- service_links/service_links.module 2008-02-26 12:01:27.000000000 -0500
+++ servic…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3648
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258106
|
- |
|
moshe_weitzman
|
organic_groups
|
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, wit…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3652
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258107
|
- |
|
darren_oh
|
xml_sitemap
|
Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permiss…
|
CWE-79
Cross-site Scripting
|
CVE-2009-3653
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258108
|
- |
|
316solutions
|
boost
|
Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot directories via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2009-3654
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258109
|
- |
|
tim_nelson
|
shared_sign-on
|
Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2009-3656
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258110
|
- |
|
tim_nelson
|
shared_sign-on
|
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2009-3657
|
2017-08-17 10:31 |
2009-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|