Vulnerabilities > Drupal > Help TIP Module

DATE CVE VULNERABILITY TITLE RISK
2006-12-14 CVE-2006-6531 Cross-Site Scripting vulnerability in Help Tip Module
Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.
network
drupal
6.8
2006-12-14 CVE-2006-6530 SQL-Injection vulnerability in Help Tip Module
SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
drupal
7.5