Vulnerabilities > Drupal > High

DATE CVE VULNERABILITY TITLE RISK
2006-10-30 CVE-2006-5608 SQL Injection vulnerability in Drupal Extended Tracker 4.7
SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "parameters from URLs."
network
low complexity
drupal
7.5
2006-10-24 CVE-2006-5476 Cross-Site Request Forgery vulnerability in Drupal
Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.
network
low complexity
drupal
7.5
2006-09-12 CVE-2006-4717 Authentication Bypass vulnerability in Drupal Pubcookie.Module 1.2.2.4/1.6.2.1
The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentication requirements and spoof identities of arbitrary users via unspecified vectors.
network
low complexity
drupal
7.5
2006-08-27 CVE-2006-4356 SQL Injection vulnerability in Drupal Easylinks Module
SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
drupal
7.5
2006-08-14 CVE-2006-4108 Input Validation vulnerability in Drupal Bibliography
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
drupal
7.5
2006-08-14 CVE-2006-4107 SQL Injection vulnerability in Drupal JOB Search 4.6Rev1.3.2
SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search.
network
low complexity
drupal
7.5
2006-07-10 CVE-2006-3473 CRLF Injection vulnerability in Drupal Form_mail Module
CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending spam messages, a different issue than CVE-2006-1225.
network
low complexity
drupal
7.5
2006-06-06 CVE-2006-2831 Input Validation vulnerability in Drupal
Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
network
low complexity
drupal
7.5
2006-06-01 CVE-2006-2742 Input Validation vulnerability in Drupal
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
network
low complexity
drupal
7.5
2005-06-09 CVE-2005-1871 Remote Security vulnerability in Drupal
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."
network
low complexity
drupal
7.5