CVE-2008-3745
- EPSS 0.96%
- Veröffentlicht 27.08.2008 15:21:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.
CVE-2008-3218
- EPSS 0.52%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, a...
CVE-2008-3219
- EPSS 0.58%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS...
CVE-2008-3220
- EPSS 0.4%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
CVE-2008-3221
- EPSS 0.42%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
CVE-2008-3222
- EPSS 1.06%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
CVE-2008-3223
- EPSS 1.14%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
CVE-2008-2999
- EPSS 0.46%
- Veröffentlicht 03.07.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple SQL injection vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
- EPSS 0.17%
- Veröffentlicht 18.06.2008 22:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attackers with "access content" permissions to bypass restrictions and modify the node hierarchy via unspeci...
CVE-2008-1729
- EPSS 0.62%
- Veröffentlicht 11.04.2008 19:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for t...