- EPSS 0.63%
- Veröffentlicht 29.09.2010 17:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by le...
- EPSS 0.63%
- Veröffentlicht 29.09.2010 17:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an asserti...
- EPSS 0.63%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an as...
CVE-2010-3092
- EPSS 0.17%
- Veröffentlicht 21.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a fil...
CVE-2010-3093
- EPSS 0.25%
- Veröffentlicht 21.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" is...
CVE-2010-3094
- EPSS 0.22%
- Veröffentlicht 21.09.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a t...
CVE-2009-4369
- EPSS 0.26%
- Veröffentlicht 21.12.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide conta...
CVE-2009-4370
- EPSS 0.16%
- Veröffentlicht 21.12.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu descript...
CVE-2009-4371
- EPSS 0.15%
- Veröffentlicht 21.12.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrar...
CVE-2009-4066
- EPSS 0.2%
- Veröffentlicht 24.11.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors r...