Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 4.7 vulnerabilities and exploits
(subscribe to this query)
6
CVSSv2
CVE-2008-4633
SQL injection vulnerability in Node Vote 5.x prior to 5.x-1.1 and 6.x prior to 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previo...
Drupal Node Clone 4.7.x-1.3
Drupal Node Clone 4.7.x-2.1
Drupal Node Clone 4.7.x-1.0
Drupal Node Clone 5
Drupal Node Clone 4.7.x-1.2
Drupal Node Clone 4.7.x-1.1
Drupal Node Clone 6
5
CVSSv2
CVE-2007-0658
The (1) Textimage 4.7.x prior to 4.7-1.2 and 5.x prior to 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x prior to 4.7-1.2 and 5.x prior to 5.x-1.1 module for Drupal allow remote malicious users to bypass the CAPTCHA test via an empty captcha element in $_SESSION.
Drupal Drupal 4.7
Drupal Drupal 4.7 Rev1.15
Drupal Drupal 5.0
Drupal Drupal 4.7.1
Drupal Drupal 4.7.2
Drupal Drupal 5.1
Drupal Textimage 4.7
Drupal Drupal 4.7.3
Drupal Drupal 4.7.4
Drupal Textimage 5.0
Drupal Drupal 4.7.5
Drupal Drupal 4.7.6
2.6
CVSSv2
CVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote malicious users to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
Drupal Drupal 4.7
Drupal Drupal 5.0
4.3
CVSSv2
CVE-2006-3570
Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal 4.6
Drupal Drupal 4.7
6.8
CVSSv2
CVE-2006-6647
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x prior to 4.7.x-3.3 and 5.x prior to 5.x-1.3 module for Drupal allows remote malicious users to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third par...
Drupal Drupal Mysite 5
Drupal Drupal Mysite 4.7
6.8
CVSSv2
CVE-2006-4646
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module before pathauto_node.inc 1.14.2.1 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal Pathauto Module 4.6
Drupal Drupal Pathauto Module 4.7
4.3
CVSSv2
CVE-2007-4064
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x prior to 5.2, and 4.7.x prior to 4.7.7, (1) allow remote malicious users to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administ...
Drupal Drupal 4.7.4
Drupal Drupal 4.7.5
Drupal Drupal 4.7.0
Drupal Drupal 4.7.1
Drupal Drupal 5.0
Drupal Drupal 5.1
Drupal Drupal 4.7.2
Drupal Drupal 4.7.3
Drupal Drupal 4.7
Drupal Drupal 4.7.6
Drupal Drupal 4.7 Rev1.15
2.6
CVSSv2
CVE-2006-4355
Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 prior to 1.5.2.1 2006/08/19 12:02:27 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal Easylinks Module 4.7
Drupal Drupal Easylinks Module 4.7.0
Drupal Drupal Easylinks Module 4.7.1
Drupal Drupal Easylinks Module 4.7.2
7.5
CVSSv2
CVE-2006-4356
SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 prior to 1.5.2.1 2006/08/19 12:02:27 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Drupal Drupal Easylinks Module 4.7.0
Drupal Drupal Easylinks Module 4.7.1
Drupal Drupal Easylinks Module 4.7.2
Drupal Drupal Easylinks Module 4.7
4.3
CVSSv2
CVE-2006-4821
Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module prior to 1.19 2006/09/12 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal Userreview Module 4.7
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »