Vulnerabilities > Dominique Clause

DATE CVE VULNERABILITY TITLE RISK
2012-11-30 CVE-2012-4471 Permissions, Privileges, and Access Controls vulnerability in Dominique Clause Search Autocomplete
The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote attackers to disable an autocompletion or change the priority order via unspecified vectors.
network
low complexity
dominique-clause drupal CWE-264
5.0
2012-09-19 CVE-2012-1638 SQL Injection vulnerability in Dominique Clause Search Autocomplete
SQL injection vulnerability in the Search Autocomplete module before 7.x-2.1 for Drupal allows remote authenticated users with the "use search_autocomplete" permission to execute arbitrary SQL commands via unspecified vectors.
6.0