Skip to main content

Vendor archive

drupal CVEs

Beta · best-effort

866 CVEs tagged to vendor drupal30 Critical, 113 High, 512 Medium, 211 Low, 0 Unrated.

CVE-2006-2742

Published Jun 1, 2006

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) databa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2743

Published Jun 1, 2006

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2260

Published May 9, 2006

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1225

Published Mar 14, 2006

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam pro…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1226

Published Mar 14, 2006

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1227

Published Mar 14, 2006

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might al…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1228

Published Mar 14, 2006

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the s…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0070

Published Jan 4, 2006

Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3973

Published Dec 3, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3974

Published Dec 3, 2005

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user prof…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3975

Published Dec 3, 2005

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a fi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2106

Published Jul 5, 2005

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1871

Published Jun 9, 2005

Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input chec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0682

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1806

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 851-866 of 866 CVEsPage 35 of 35