Vulnerabilities > Drupal
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-07-22 | CVE-2014-5022 | Cross-Site Scripting vulnerability in Drupal Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field. | 4.3 |
2014-07-22 | CVE-2014-5021 | Cross-Site Scripting vulnerability in Drupal Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label. | 2.1 |
2014-07-22 | CVE-2014-5020 | Permissions, Privileges, and Access Controls vulnerability in Drupal The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. | 4.9 |
2014-07-22 | CVE-2014-5019 | Improper Input Validation vulnerability in Drupal The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use. | 5.0 |
2014-05-29 | CVE-2013-4178 | Improper Authentication vulnerability in Google Authenticator Login Project GA Login The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP). | 5.0 |
2014-05-29 | CVE-2013-4177 | Permissions, Privileges, and Access Controls vulnerability in Google Authenticator Login Project GA Login The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors. | 5.0 |
2014-05-20 | CVE-2013-4380 | Cross-Site Scripting vulnerability in Mediafront Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings. | 2.1 |
2014-05-17 | CVE-2013-4498 | Permissions, Privileges, and Access Controls vulnerability in Florian Weber Spaces The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content. | 2.1 |
2014-05-13 | CVE-2013-4504 | Permissions, Privileges, and Access Controls vulnerability in Monster Menus Module Project Monster Menus The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL. | 2.6 |
2014-05-13 | CVE-2013-4502 | Permissions, Privileges, and Access Controls vulnerability in Nathan Haug Filefield Sources The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file. | 4.0 |