Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Drupal
(Drupal)Repositories |
• https://github.com/jquery/jquery-ui
• https://github.com/symfony/symfony |
#Vulnerabilities | 253 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2007-10-19 | CVE-2007-5593 | install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified. | Drupal, Fedora | N/A | ||
2007-01-31 | CVE-2007-0626 | The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines." | Drupal | N/A | ||
2007-01-09 | CVE-2007-0136 | Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information. | Drupal | N/A | ||
2008-07-18 | CVE-2008-3223 | SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields." | Drupal, Fedora | N/A | ||
2008-07-18 | CVE-2008-3222 | Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. | Drupal, Fedora | N/A | ||
2008-07-18 | CVE-2008-3221 | Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities. | Drupal, Fedora | N/A | ||
2008-07-18 | CVE-2008-3220 | Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | Drupal, Fedora | N/A | ||
2008-07-18 | CVE-2008-3219 | The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism. | Drupal, Fedora | N/A | ||
2020-01-14 | CVE-2011-2715 | An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. | Data, Drupal | N/A | ||
2020-01-14 | CVE-2011-2714 | A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display. | Data, Drupal | N/A |