Vulnerabilities > Drupal > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-12-31 CVE-2009-4527 Permissions, Privileges, and Access Controls vulnerability in Niif Shib Auth
The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser.
local
low complexity
niif drupal CWE-264
4.6
2009-12-31 CVE-2009-4526 Permissions, Privileges, and Access Controls vulnerability in Joao Ventura Print
The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, does not properly enforce privilege requirements, which allows remote attackers to read page titles by requesting a "Send to friend" form.
network
low complexity
joao-ventura drupal CWE-264
5.0
2009-12-31 CVE-2009-4525 Cross-Site Scripting vulnerability in Joao Ventura Print
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via crafted data in a list of links.
4.3
2009-12-31 CVE-2009-4524 Cross-Site Scripting vulnerability in Nancy Wichmann Realname 6.X1.0/6.X1.1/6.X1.2
Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (aka real name) element.
4.3
2009-12-31 CVE-2009-4520 Permissions, Privileges, and Access Controls vulnerability in Kristof DE Jaeger Commentreference
The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access restrictions and read comments by using the autocomplete path.
network
low complexity
kristof-de-jaeger drupal CWE-264
5.0
2009-12-31 CVE-2009-4518 Cross-Site Scripting vulnerability in Mark Burton Insertnode 5.X1.1/5.X1.X
Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via an inserted node.
4.3
2009-12-31 CVE-2009-4517 Cross-Site Request Forgery (CSRF) vulnerability in Nanwich FAQ ASK
Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that access unpublished content.
6.8
2009-12-31 CVE-2009-4516 Cross-Site Scripting vulnerability in Nanwich FAQ ASK
Cross-site scripting (XSS) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2009-12-31 CVE-2009-4515 Permissions, Privileges, and Access Controls vulnerability in Speedtech Storm
The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecified vectors.
network
low complexity
speedtech drupal CWE-264
5.0
2009-12-04 CVE-2009-4207 Cross-Site Scripting vulnerability in Nathan Haug Webform
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a submission.
4.3