Vulnerabilities > Earl Miles
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2012-02-17 | CVE-2011-4113 | SQL Injection vulnerability in Earl Miles Views SQL injection vulnerability in the Views module before 6.x-2.13 for Drupal allows remote attackers to execute arbitrary SQL commands via vectors related to "filters/arguments on certain types of views with specific configurations of arguments." | 7.5 |
2012-01-24 | CVE-2012-0914 | Cross-Site Scripting vulnerability in Earl Miles Panels Cross-site scripting (XSS) vulnerability in display_renderers/panels_renderer_editor.class.php in the admin view in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before 7.x-3.0 for Drupal allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the Region title. | 4.3 |
2010-12-23 | CVE-2010-4521 | Cross-Site Scripting vulnerability in Earl Miles Views Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path. | 4.3 |
2010-12-23 | CVE-2010-4520 | Cross-Site Scripting vulnerability in Earl Miles Views Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title. | 4.3 |
2010-12-23 | CVE-2010-4519 | Cross-Site Request Forgery (CSRF) vulnerability in Earl Miles Views Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views. | 6.8 |