Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.1 CVE-2007-5595 CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers … Drupal 4.7.8 / 5.3+ Fix from $1,6002007-10-19 MEDIUM 6.8 CVE-2007-5416 Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric param… Drupal after 5.2 Fix from $1,6002007-10-12 MEDIUM 5.0 CVE-2007-4436 The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not … Project after 5.0 Fix from $1,6002007-08-20 HIGH 7.8 CVE-2007-3689 The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonom… Print Module after 5.x-1.1 Fix from $1,9502007-07-11 HIGH 7.8 CVE-2007-3690 The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxon… Forward Module after 5.x-1.1 Fix from $1,9502007-07-11 HIGH 7.5 CVE-2007-2160 Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.*… Database Administration Module Patch available Fix from $1,9502007-04-22 MEDIUM 6.0 CVE-2007-1360 Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to access and modify other users' … Nodefamily Patch available Fix from $1,6002007-03-08 MEDIUM 6.5 CVE-2006-7109 Unrestricted file upload vulnerability in IMCE before 1.6, a Drupal module, allows remote authenticated users to upload arbitrary PHP code via a file… Imce Module after 1.5 Fix from $1,6002007-03-05 MEDIUM 5.5 CVE-2006-7110 Directory traversal vulnerability in the delete function in IMCE before 1.6, a Drupal module, allows remote authenticated users to delete arbitrary f… Imce Module after 1.5 Fix from $1,6002007-03-05 HIGH 7.5 CVE-2007-1033 Unspecified vulnerability in the Secure site 4.7.x-1.x-dev and 5.x-1.x-dev module for Drupal allows remote attackers to bypass access restrictions vi… Secure Site Module Patch available Fix from $1,9502007-02-21 HIGH 7.5 CVE-2007-1035 Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote att… Audio Module Patch available Fix from $1,9502007-02-21 MEDIUM 5.0 CVE-2007-0658 The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 modul… Drupal Patch available Fix from $1,6002007-02-01 MEDIUM 6.5 CVE-2007-0626 The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post … Drupal 4.7.6 / 5.1+ Fix from $1,6002007-01-31 HIGH 8.5 CVE-2007-0505 Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authentica… Project Patch available Fix from $1,9502007-01-26 MEDIUM 6.0 CVE-2007-0506 The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users… Project Patch available Fix from $1,6002007-01-26 MEDIUM 6.0 CVE-2007-0507 SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated u… Acidfree Patch available Fix from $1,6002007-01-26 MEDIUM 6.8 CVE-2006-6646 Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.… Drupal Project Patch available Fix from $1,6002006-12-20 MEDIUM 6.8 CVE-2006-6647 Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inj… Drupal Mysite Patch available Fix from $1,6002006-12-20 HIGH 7.5 CVE-2006-6528 The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitors' session IDs to all participants, which allows remote attackers to hija… Chatroom Module after 4.7 Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-6529 The Chatroom Module before 4.7.x.-1.0 for Drupal displays private messages in a chatroom's last messages overview, which allows remote attackers to o… Chatroom Module Patch available Fix from $1,9502006-12-14 HIGH 7.5 CVE-2006-6530 SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecif… Help Tip Module after 4.7 Fix from $1,9502006-12-14 MEDIUM 6.8 CVE-2006-6531 Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or… Help Tip Module after 4.7 Fix from $1,6002006-12-14 MEDIUM 6.8 CVE-2006-6386 Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release syst… Cvs Management And Tracker Patch available Fix from $1,6002006-12-08 HIGH 7.5 CVE-2006-5608 SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands vi… Extended Tracker Patch available Fix from $1,9502006-10-30 HIGH 7.5 CVE-2006-5476 Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized … Drupal Mitigation only Fix from $1,9502006-10-24 MEDIUM 6.8 CVE-2006-5475 Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to … Drupal Patch available Fix from $1,6002006-10-24 MEDIUM 6.8 CVE-2006-4947 Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote attackers to inject arbitrary … Search Keyword Module after 1.15 Fix from $1,6002006-09-23 HIGH 7.5 CVE-2006-4717 The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/… Drupal Pubcookie Module Patch available Fix from $1,9502006-09-12 MEDIUM 6.8 CVE-2006-4646 Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module befor… Drupal Pathauto Module Patch available Fix from $1,6002006-09-08 HIGH 7.5 CVE-2006-4356 SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute a… Drupal Easylinks Module Patch available Fix from $1,9502006-08-27