Vulnerabilities > Drupal > Drupal > 6.26

DATE CVE VULNERABILITY TITLE RISK
2013-01-03 CVE-2012-5652 Information Exposure vulnerability in Drupal
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
network
low complexity
drupal CWE-200
5.0
2013-01-03 CVE-2012-5651 Permissions, Privileges, and Access Controls vulnerability in Drupal
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
network
low complexity
drupal CWE-264
5.0
2012-05-21 CVE-2012-2922 Information Exposure vulnerability in Drupal
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
network
low complexity
drupal CWE-200
5.0
2009-09-24 CVE-2009-3352 Unspecified vulnerability in Drupal
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
network
low complexity
drupal
critical
10.0