Search CVE reports
31 – 40 of 48 results
CVE-2008-3223
Medium prioritySQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-3222
Low prioritySome fixes available 1 of 4
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-3221
Unknown priorityCross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-3220
Medium prioritySome fixes available 1 of 4
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-3219
Low prioritySome fixes available 1 of 4
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an...
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-3218
Low priorityMultiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on...
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-1133
Low priorityThe Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-1131
Low priorityCross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-0274
Low prioritySome fixes available 4 of 8
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |
CVE-2008-0273
Low prioritySome fixes available 2 of 4
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not...
2 affected packages
drupal, drupal5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
drupal | — | — | — | — | — |
drupal5 | — | — | — | — | — |