Vulnerabilities > Carlos Carvalhar

DATE CVE VULNERABILITY TITLE RISK
2012-12-03 CVE-2012-5550 SQL Injection vulnerability in Carlos Carvalhar Time Spent 6.X2.X/7.X2.X
SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
carlos-carvalhar drupal CWE-89
7.5
2012-12-03 CVE-2012-5549 Cross-Site Request Forgery (CSRF) vulnerability in Carlos Carvalhar Time Spent 6.X2.X/7.X2.X
Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
6.8
2012-12-03 CVE-2012-5548 Cross-Site Scripting vulnerability in Carlos Carvalhar Time Spent 6.X2.X/7.X2.X
Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3