Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal MEDIUM 5.0
CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying t…

Patch available
Fix from $1,600 2010-09-29
Drupal MEDIUM 5.5
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configurat…

Patch available
Fix from $1,600 2010-09-21
Drupal MEDIUM 6.8
CVE-2009-4066

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.…

Patch available
Fix from $1,600 2009-11-24
Drupal HIGH 10.0
CVE-2009-3352

Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

Fix: 7.0+
Fix from $1,950 2009-09-24
Drupal MEDIUM 6.5
CVE-2009-2372

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator…

Fix: 6.13+
Fix from $1,600 2009-07-08
Services Module For Drupal MEDIUM 6.4
CVE-2009-2035

Unspecified vulnerability in Services 6.x before 6.x-0.14, a module for Drupal, when key-based access is enabled, allows remote attackers to read or …

Fix: after 6.x-0.13
Fix from $1,600 2009-06-12
Nodeaccess Userreference HIGH 7.5
CVE-2009-1507

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user refere…

Patch available
Fix from $1,950 2009-05-01
News Page MEDIUM 6.5
CVE-2009-1505

SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and …

Patch available
Fix from $1,600 2009-05-01
Drupal MEDIUM 6.8
CVE-2008-6532

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers …

Patch available
Fix from $1,600 2009-03-26
Tasklist HIGH 10.0
CVE-2009-1034

SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attac…

Fix: after 5.x-2.x
Fix from $1,950 2009-03-20
Plus1 MEDIUM 6.8
CVE-2009-1036

Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for c…

Fix: after 6.x-2.5
Fix from $1,600 2009-03-20
Print MEDIUM 5.0
CVE-2009-1037

Unspecified vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a …

Patch available
Fix from $1,600 2009-03-20
Comment Mail MEDIUM 6.8
CVE-2008-6384

Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack …

Patch available
Fix from $1,600 2009-03-02
Storm MEDIUM 6.0
CVE-2008-6383

SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, …

Patch available
Fix from $1,600 2009-03-02
User Karma Module MEDIUM 6.5
CVE-2008-6276

Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote a…

Patch available
Fix from $1,600 2009-02-25
Drupal HIGH 9.3
CVE-2008-6171

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attack…

Patch available
Fix from $1,950 2009-02-19
Localization Client MEDIUM 6.8
CVE-2008-6169

Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x …

Fix: after 6.x-1.5
Fix from $1,600 2009-02-19
Semantically Interconnected Online Communities MEDIUM 5.0
CVE-2008-6160

Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement men…

Fix: after 6.x_1.0
Fix from $1,600 2009-02-18
Everyblog HIGH 7.5
CVE-2008-6134

SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified …

Mitigation only
Fix from $1,950 2009-02-14
Everyblog HIGH 7.5
CVE-2008-6136

Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrat…

No fix yet
Fix from $1,950 2009-02-14
Everyblog HIGH 7.5
CVE-2008-6137

EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.

No fix yet
Fix from $1,950 2009-02-14
Views HIGH 7.5
CVE-2008-6020

SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecifi…

Fix: after 6.x-2.1
Fix from $1,950 2009-02-02
Ajax Checklist MEDIUM 6.0
CVE-2008-5998

Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote au…

Patch available
Fix from $1,600 2009-01-28
Drupal HIGH 7.5
CVE-2008-4793

The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors…

Fix: after 5.10
Fix from $1,950 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4789

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restricti…

Fix: after 6.4
Fix from $1,600 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4790

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to…

Fix: after 5.10
Fix from $1,600 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4791

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and success…

Fix: 5.11 / 6.5+
Fix from $1,600 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4792

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form…

Fix: 5.11 / 6.5+
Fix from $1,600 2008-10-29
Node Clone MEDIUM 6.0
CVE-2008-4633

SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, …

Mitigation only
Fix from $1,600 2008-10-21
Shindig Integrator HIGH 7.5
CVE-2008-4597

Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via u…

Mitigation only
Fix from $1,950 2008-10-17