Skip to main content

Vendor/product archive

drupal / aggregation_module CVEs

Beta · best-effort

4 CVEs tagged to drupal / aggregation_module1 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2008-2998

Published Jul 3, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2999

Published Jul 3, 2008

Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3000

Published Jul 3, 2008

The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote attackers to bypass intend…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3001

Published Jul 3, 2008

The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed tha…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1