Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Drupal MEDIUM 5.1
CVE-2006-4120

Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to injec…

Fix: after 4.6
Fix from $1,600 2006-08-14
Job Search HIGH 7.5
CVE-2006-4107

SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2006-08-14
Bibliography Module HIGH 7.5
CVE-2006-4108

SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remot…

Fix: after 4.7_rev1.13.2.4
Fix from $1,950 2006-08-14
Form Mail Module HIGH 7.5
CVE-2006-3473

CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending sp…

Fix: after 1.8.2.1
Fix from $1,950 2006-07-10
Drupal HIGH 7.5
CVE-2006-2831

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled withi…

Patch available
Fix from $1,950 2006-06-06
Drupal HIGH 7.5
CVE-2006-2742

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2…

Patch available
Fix from $1,950 2006-06-01
Drupal MEDIUM 5.1
CVE-2006-2743EPSS 11%

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remo…

Patch available
Fix from $1,600 2006-06-01
Drupal MEDIUM 5.1
CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to c…

Patch available
Fix from $1,600 2006-03-14
Drupal MEDIUM 5.0
CVE-2006-1225

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail message…

Patch available
Fix from $1,600 2006-03-14
Drupal MEDIUM 6.4
CVE-2005-3974

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers t…

Patch available
Fix from $1,600 2005-12-03
Drupal MEDIUM 5.0
CVE-2005-2106

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or p…

Patch available
Fix from $1,600 2005-07-05
Drupal HIGH 7.5
CVE-2005-1871

Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain pri…

Mitigation only
Fix from $1,950 2005-06-09