Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal project 4.7 vulnerabilities and exploits
(subscribe to this query)
756
VMScore
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
Drupal Project 4.6
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
534
VMScore
CVE-2007-0506
The project_issue_access function in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue informat...
Drupal Project 4.6
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
605
VMScore
CVE-2006-6646
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters, which do not use t...
Drupal Drupal Project 4.6 1.0
Drupal Drupal Project 4.7
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project 4.6
Drupal Drupal Project 4.7 1.0
Drupal Drupal Project 4.7 2.0
383
VMScore
CVE-2008-0576
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev prior to 20080130 in the 5.x-2.x series, 5.x-1.2 and previous versions in the 5.x-1.x series, 4.7.x-2.6 and previous versions in the 4.7.x-2.x series, and 4.7.x-1.6 and previous versions in ...
Drupal Project Issue Tracking Module 5
Drupal Project Issue Tracking Module 4.7
570
VMScore
CVE-2008-0577
The Project Issue Tracking module 5.x-2.x-dev prior to 20080130 in the 5.x-2.x series, 5.x-1.2 and previous versions in the 5.x-1.x series, 4.7.x-2.6 and previous versions in the 4.7.x-2.x series, and 4.7.x-1.6 and previous versions in the 4.7.x-1.x series for Drupal (1) does not...
Drupal Project Issue Tracking Module 4.7
Drupal Project Issue Tracking Module 5.0
312
VMScore
CVE-2007-1368
The Project issue tracking module prior to 4.7.x-1.3, 4.7.x-2.* prior to 4.7.x-2.3, and 5 prior to 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node i...
Drupal Drupal Project Issue Tracking 4.7 1.2
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 2.1
Drupal Drupal Project Issue Tracking 4.7 2.2
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project Issue Tracking 5.0 0.1
Drupal Drupal Project Issue Tracking 5.7 1.1
312
VMScore
CVE-2007-5228
Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module prior to 4.7.x-1.5, 4.7.x-2.x prior to 4.7.x-2.5, and 5.x-1.x prior to 5.x-1.1 for Drupal allows remote authenticated users with project create or edit permissions to i...
Drupal Drupal Project Issue Tracking 4.7 1.2
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 2.1
Drupal Drupal Project Issue Tracking 4.7 2.2
Drupal Drupal Project Issue Tracking 5.0 0.1
Drupal Drupal Project Issue Tracking 4.7 1.0
515
VMScore
CVE-2006-2743
Drupal 4.6.x prior to 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote malicious users to upload, modify, or execute arbitrary files in the files directory.
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.6.1
Drupal Drupal 4.6.2
Drupal Drupal 4.6.5
Drupal Drupal 4.6.6
Drupal Drupal 4.7.0
Drupal Drupal 4.6
Drupal Drupal 4.6.0
1 EDB exploit
445
VMScore
CVE-2007-4436
The Drupal Project module prior to 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module prior to 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote malicious users to (1) obtain sensitive via the Tracker Module and the Recent...
Drupal Project
Drupal Project Issue Tracking Module
668
VMScore
CVE-2006-2831
Drupal 4.6.x prior to 4.6.8 and 4.7.x prior to 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote malicious users to execute arbitrary code by uploading a file with multiple extensions, a variant of...
Drupal Drupal 4.6.0
Drupal Drupal 4.6.1
Drupal Drupal 4.7.1
Drupal Drupal 4.6
Drupal Drupal 4.6.6
Drupal Drupal 4.6.7
Drupal Drupal 4.7.0
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.6.5
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4761
command injection
CVE-2024-3676
IDOR
CVE-2024-30039
CVE-2024-32113
CVE-2024-30049
CVE-2024-4776
SQL injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »