CVE-2009-2374
- EPSS 0.26%
- Published 08.07.2009 15:30:01
- Last modified 09.04.2025 00:30:58
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web s...
CVE-2009-1844
- EPSS 0.13%
- Published 01.06.2009 14:30:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explo...
CVE-2009-1575
- EPSS 0.74%
- Published 06.05.2009 17:30:09
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta ta...
CVE-2009-1576
- EPSS 0.8%
- Published 06.05.2009 17:30:09
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a craf...
CVE-2008-6532
- EPSS 0.33%
- Published 26.03.2009 21:00:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing ...
CVE-2008-6533
- EPSS 0.38%
- Published 26.03.2009 21:00:00
- Last modified 09.04.2025 00:30:58
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspe...
CVE-2009-1047
- EPSS 0.2%
- Published 23.03.2009 20:00:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via ...
CVE-2008-6170
- EPSS 0.24%
- Published 19.02.2009 15:30:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
CVE-2008-6171
- EPSS 2.98%
- Published 19.02.2009 15:30:00
- Last modified 09.04.2025 00:30:58
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
- EPSS 0.21%
- Published 29.10.2008 15:31:35
- Last modified 09.04.2025 00:30:58
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."