Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal MEDIUM 5.1
CVE-2007-5595

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers …

Fix: 4.7.8 / 5.3+
Fix from $1,600 2007-10-19
Drupal MEDIUM 6.8
CVE-2007-5416

Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric param…

Fix: after 5.2
Fix from $1,600 2007-10-12
Project MEDIUM 5.0
CVE-2007-4436

The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not …

Fix: after 5.0
Fix from $1,600 2007-08-20
Print Module HIGH 7.8
CVE-2007-3689

The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonom…

Fix: after 5.x-1.1
Fix from $1,950 2007-07-11
Forward Module HIGH 7.8
CVE-2007-3690

The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxon…

Fix: after 5.x-1.1
Fix from $1,950 2007-07-11
Database Administration Module HIGH 7.5
CVE-2007-2160

Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.*…

Patch available
Fix from $1,950 2007-04-22
Nodefamily MEDIUM 6.0
CVE-2007-1360

Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' …

Patch available
Fix from $1,600 2007-03-08
Imce Module MEDIUM 6.5
CVE-2006-7109

Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a file…

Fix: after 1.5
Fix from $1,600 2007-03-05
Imce Module MEDIUM 5.5
CVE-2006-7110

Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary f…

Fix: after 1.5
Fix from $1,600 2007-03-05
Secure Site Module HIGH 7.5
CVE-2007-1033

Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions vi…

Patch available
Fix from $1,950 2007-02-21
Audio Module HIGH 7.5
CVE-2007-1035

Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote att…

Patch available
Fix from $1,950 2007-02-21
Drupal MEDIUM 5.0
CVE-2007-0658

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 modul…

Patch available
Fix from $1,600 2007-02-01
Drupal MEDIUM 6.5
CVE-2007-0626

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post …

Fix: 4.7.6 / 5.1+
Fix from $1,600 2007-01-31
Project HIGH 8.5
CVE-2007-0505

Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authentica…

Patch available
Fix from $1,950 2007-01-26
Project MEDIUM 6.0
CVE-2007-0506

The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users…

Patch available
Fix from $1,600 2007-01-26
Acidfree MEDIUM 6.0
CVE-2007-0507

SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated u…

Patch available
Fix from $1,600 2007-01-26
Drupal Project MEDIUM 6.8
CVE-2006-6646

Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.…

Patch available
Fix from $1,600 2006-12-20
Drupal Mysite MEDIUM 6.8
CVE-2006-6647

Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inj…

Patch available
Fix from $1,600 2006-12-20
Chatroom Module HIGH 7.5
CVE-2006-6528

The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hija…

Fix: after 4.7
Fix from $1,950 2006-12-14
Chatroom Module HIGH 7.5
CVE-2006-6529

The Chatroom Module before 4.7.x.-1.0 for Drupal displays private messages in a chatroom's last messages overview, which allows remote attackers to o…

Patch available
Fix from $1,950 2006-12-14
Help Tip Module HIGH 7.5
CVE-2006-6530

SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecif…

Fix: after 4.7
Fix from $1,950 2006-12-14
Help Tip Module MEDIUM 6.8
CVE-2006-6531

Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or…

Fix: after 4.7
Fix from $1,600 2006-12-14
Cvs Management And Tracker MEDIUM 6.8
CVE-2006-6386

Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release syst…

Patch available
Fix from $1,600 2006-12-08
Extended Tracker HIGH 7.5
CVE-2006-5608

SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands vi…

Patch available
Fix from $1,950 2006-10-30
Drupal HIGH 7.5
CVE-2006-5476

Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized …

Mitigation only
Fix from $1,950 2006-10-24
Drupal MEDIUM 6.8
CVE-2006-5475

Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to …

Patch available
Fix from $1,600 2006-10-24
Search Keyword Module MEDIUM 6.8
CVE-2006-4947

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote attackers to inject arbitrary …

Fix: after 1.15
Fix from $1,600 2006-09-23
Drupal Pubcookie Module HIGH 7.5
CVE-2006-4717

The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/…

Patch available
Fix from $1,950 2006-09-12
Drupal Pathauto Module MEDIUM 6.8
CVE-2006-4646

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module befor…

Patch available
Fix from $1,600 2006-09-08
Drupal Easylinks Module HIGH 7.5
CVE-2006-4356

SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute a…

Patch available
Fix from $1,950 2006-08-27