Vulnerabilities > Joao Ventura

DATE CVE VULNERABILITY TITLE RISK
2012-11-22 CVE-2012-2084 Cross-Site Scripting vulnerability in Joao Ventura Print
Cross-site scripting (XSS) vulnerability in the Printer, email and PDF versions module 6.x-1.x before 6.x-1.15 and 7.x-1.x before 7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably the PATH_INFO.
4.3
2009-12-31 CVE-2009-4526 Permissions, Privileges, and Access Controls vulnerability in Joao Ventura Print
The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, does not properly enforce privilege requirements, which allows remote attackers to read page titles by requesting a "Send to friend" form.
network
low complexity
joao-ventura drupal CWE-264
5.0
2009-12-31 CVE-2009-4525 Cross-Site Scripting vulnerability in Joao Ventura Print
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via crafted data in a list of links.
4.3
2009-09-16 CVE-2009-3210 Cross-Site Scripting vulnerability in Joao Ventura Print
Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x before 6.x-1.8, a module for Drupal, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
3.5