Vulnerabilities > Biblio Autocomplete Project

DATE CVE VULNERABILITY TITLE RISK
2014-08-14 CVE-2014-5250 SQL Injection and Access Bypass vulnerability in Drupal Biblio Autocomplete Module
Unspecified vulnerability in the AJAX autocompletion callback in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to access data via unspecified vectors.
network
low complexity
biblio-autocomplete-project
7.5
2014-08-14 CVE-2014-5249 SQL Injection vulnerability in Biblio Autocomplete Project Biblio Autocomplete
SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
biblio-autocomplete-project CWE-89
7.5