Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2006-6530

Published Dec 14, 2006

SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6531

Published Dec 14, 2006

Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6386

Published Dec 8, 2006

Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5608

Published Oct 30, 2006

SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5475

Published Oct 24, 2006

Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5476

Published Oct 24, 2006

Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5477

Published Oct 24, 2006

Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4947

Published Sep 23, 2006

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4949

Published Sep 23, 2006

Cross-site scripting (XSS) vulnerability in the Drupal 4.6 Site Profile Directory (profile_pages.module) before 1.1.2.1 and the Drupal 4.7 Site Profile Directory (profile_pages.mo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4821

Published Sep 15, 2006

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4717

Published Sep 12, 2006

The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4646

Published Sep 8, 2006

Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module before pathauto_node.inc 1.14.2.1 a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4355

Published Aug 27, 2006

Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web scrip…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4356

Published Aug 27, 2006

SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute arbitrary SQL commands via unsp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4360

Published Aug 27, 2006

Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permissio…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4120

Published Aug 14, 2006

Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4107

Published Aug 14, 2006

SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4108

Published Aug 14, 2006

SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4109

Published Aug 14, 2006

Cross-site scripting (XSS) vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4002

Published Aug 7, 2006

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the ms…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3570

Published Jul 13, 2006

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3473

Published Jul 10, 2006

CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending spam messages, a different issue…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2831

Published Jun 6, 2006

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2832

Published Jun 6, 2006

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web s…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2833

Published Jun 6, 2006

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not pr…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 826-850 of 866 CVEsPage 34 of 35