Vulnerabilities > Drupal

DATE CVE VULNERABILITY TITLE RISK
2014-07-22 CVE-2014-5022 Cross-Site Scripting vulnerability in Drupal
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.
network
drupal CWE-79
4.3
2014-07-22 CVE-2014-5021 Cross-Site Scripting vulnerability in Drupal
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
network
high complexity
drupal CWE-79
2.1
2014-07-22 CVE-2014-5020 Permissions, Privileges, and Access Controls vulnerability in Drupal
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
network
drupal CWE-264
4.9
2014-07-22 CVE-2014-5019 Improper Input Validation vulnerability in Drupal
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.
network
low complexity
drupal CWE-20
5.0
2014-05-29 CVE-2013-4178 Improper Authentication vulnerability in Google Authenticator Login Project GA Login
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
5.0
2014-05-29 CVE-2013-4177 Permissions, Privileges, and Access Controls vulnerability in Google Authenticator Login Project GA Login
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.
5.0
2014-05-20 CVE-2013-4380 Cross-Site Scripting vulnerability in Mediafront
Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.
network
high complexity
mediafront drupal CWE-79
2.1
2014-05-17 CVE-2013-4498 Permissions, Privileges, and Access Controls vulnerability in Florian Weber Spaces
The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.
network
high complexity
florian-weber drupal CWE-264
2.1
2014-05-13 CVE-2013-4504 Permissions, Privileges, and Access Controls vulnerability in Monster Menus Module Project Monster Menus
The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.
network
high complexity
monster-menus-module-project drupal CWE-264
2.6
2014-05-13 CVE-2013-4502 Permissions, Privileges, and Access Controls vulnerability in Nathan Haug Filefield Sources
The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.
network
low complexity
nathan-haug drupal CWE-264
4.0