Vulnerabilities > Drupal > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-10-30 | CVE-2006-5608 | SQL Injection vulnerability in Drupal Extended Tracker 4.7 SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "parameters from URLs." | 7.5 |
2006-10-24 | CVE-2006-5476 | Cross-Site Request Forgery vulnerability in Drupal Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors. | 7.5 |
2006-09-12 | CVE-2006-4717 | Authentication Bypass vulnerability in Drupal Pubcookie.Module 1.2.2.4/1.6.2.1 The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentication requirements and spoof identities of arbitrary users via unspecified vectors. | 7.5 |
2006-08-27 | CVE-2006-4356 | SQL Injection vulnerability in Drupal Easylinks Module SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2006-08-14 | CVE-2006-4108 | Input Validation vulnerability in Drupal Bibliography SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 7.5 |
2006-08-14 | CVE-2006-4107 | SQL Injection vulnerability in Drupal JOB Search 4.6Rev1.3.2 SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search. | 7.5 |
2006-07-10 | CVE-2006-3473 | CRLF Injection vulnerability in Drupal Form_mail Module CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending spam messages, a different issue than CVE-2006-1225. | 7.5 |
2006-06-06 | CVE-2006-2831 | Input Validation vulnerability in Drupal Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743. | 7.5 |
2006-06-01 | CVE-2006-2742 | Input Validation vulnerability in Drupal SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc. | 7.5 |
2005-06-09 | CVE-2005-1871 | Remote Security vulnerability in Drupal Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly." | 7.5 |