Vulnerabilities > Moshe Weitzman

DATE CVE VULNERABILITY TITLE RISK
2012-08-14 CVE-2012-2081 Permissions, Privileges, and Access Controls vulnerability in Moshe Weitzman Organic Groups
The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module.
network
low complexity
moshe-weitzman drupal CWE-264
5.0
2012-06-27 CVE-2012-3800 Cross-Site Scripting vulnerability in Moshe Weitzman Organic Groups
Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.
network
high complexity
moshe-weitzman drupal CWE-79
2.1
2012-06-27 CVE-2012-2721 Permissions, Privileges, and Access Controls vulnerability in Moshe Weitzman Organic Groups
The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "access content" permission removed, which allows remote attackers to bypass access restrictions and possibly have other unspecified impact.
6.8
2009-12-31 CVE-2009-4528 Permissions, Privileges, and Access Controls vulnerability in Moshe Weitzman OG Vocab 6.X1.0/6.X1.X
The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restrictions, and create, modify, or read a vocabulary, via unspecified vectors.
network
low complexity
moshe-weitzman drupal CWE-264
6.5
2009-10-26 CVE-2009-3786 Cross-Site Scripting vulnerability in Moshe Weitzman OG Vocab 5.X1.0/5.X1.Xdev
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title.
4.3
2009-10-09 CVE-2009-3652 Cross-Site Scripting vulnerability in Moshe Weitzman Organic Groups
Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or HTML via the User-Agent HTTP header, a different issue than CVE-2008-3095.
3.5
2009-09-28 CVE-2009-3435 Cross-Site Scripting vulnerability in Moshe Weitzman Devel
Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a variable name.
4.3