CVE-2009-4370
- EPSS 0.89%
- Veröffentlicht 21.12.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:13:32
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu descript...
CVE-2009-4371
- EPSS 0.89%
- Veröffentlicht 21.12.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:13:32
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrar...
CVE-2009-4066
- EPSS 0.72%
- Veröffentlicht 24.11.2009 02:30:00
- Zuletzt bearbeitet 16.06.2026 23:12:58
Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors r...
CVE-2009-3479
- EPSS 1.07%
- Veröffentlicht 30.09.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:41
Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows remote attackers, with "create content displayed by the Bibliography module" permissions, to inject arbitrary we...
- EPSS 1.96%
- Veröffentlicht 24.09.2009 16:30:01
- Zuletzt bearbeitet 16.06.2026 23:11:26
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
CVE-2009-3156
- EPSS 1.22%
- Veröffentlicht 10.09.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:02
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script o...
CVE-2009-2372
- EPSS 2.31%
- Veröffentlicht 08.07.2009 15:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:18
Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTM...
CVE-2009-2373
- EPSS 1.77%
- Veröffentlicht 08.07.2009 15:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:18
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2009-2374
- EPSS 1.4%
- Veröffentlicht 08.07.2009 15:30:01
- Zuletzt bearbeitet 16.06.2026 23:09:18
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web s...
CVE-2009-1844
- EPSS 0.86%
- Veröffentlicht 01.06.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:10
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explo...