Vulnerabilities > Drupal > Content Construction KIT

DATE CVE VULNERABILITY TITLE RISK
2009-03-26 CVE-2009-1069 Cross-Site Scripting vulnerability in Drupal Content Construction KIT
Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.
network
drupal CWE-79
4.3
2009-02-20 CVE-2008-6229 Cross-Site Scripting vulnerability in Drupal Content Construction KIT
Cross-site scripting (XSS) vulnerability in the administrative interface in Drupal Content Construction Kit (CCK) 5.x before 5.x-1.10 and 6.x before 6.x-2.0, a module for Drupal, allows remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via (1) field labels and (2) content-type names.
network
drupal CWE-79
3.5
2007-08-15 CVE-2007-4363 HTML-injection vulnerability in Drupal Content Construction KIT 4.7/5.2
Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the autocomplete text field widget without Views.module.
network
drupal
4.3