Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 4.6 vulnerabilities and exploits
(subscribe to this query)
8.5
CVSSv2
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
Drupal Project 4.6
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
7.5
CVSSv2
CVE-2007-6299
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x prior to 4.7.9 and 5.x prior to 5.4 allow remote malicious users to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ...
Drupal Drupal 4.4.1
Drupal Drupal 4.4.2
Drupal Drupal 4.5.5
Drupal Drupal 4.5.6
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.7
Drupal Drupal 4.7.1
Drupal Drupal 4.7.8
Drupal Drupal 4.7 Rev1.15
Drupal Drupal 4.2.0 Rc
Drupal Drupal 4.4.0
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.6.1
Drupal Drupal 4.6.10
Drupal Drupal 4.6.11
Drupal Drupal 4.6.8
Drupal Drupal 4.6.9
Drupal Drupal 4.7.6
Drupal Drupal 4.7.7
Drupal Drupal 4.0.0
7.5
CVSSv2
CVE-2007-2160
Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and prior to 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote malicious users to perform unauthorized actions as an arbitrary user, a related issue to CVE-200...
Drupal Database Administration Module 4.6
Drupal Database Administration Module 4.7
7.5
CVSSv2
CVE-2006-5476
Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x prior to 4.6.10 and 4.7.x prior to 4.7.4 allows remote malicious users to perform unauthorized actions as an arbitrary user via unspecified vectors.
Drupal Drupal 4.6.5
Drupal Drupal 4.6.6
Drupal Drupal 4.7.3
Drupal Drupal 4.6.1
Drupal Drupal 4.6.2
Drupal Drupal 4.6.9
Drupal Drupal 4.7.0
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.7.1
Drupal Drupal 4.7.2
Drupal Drupal 4.6.0
Drupal Drupal 4.6.7
Drupal Drupal 4.6.8
7.5
CVSSv2
CVE-2006-4717
The login redirection mechanism in the Drupal 4.7 Pubcookie module prior to 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module prior to 1.6.2.1 2006/09/07 allows remote malicious users to bypass authentication requirements and spoof identities of arbitrary users via unspecifi...
Drupal Drupal Pubcookie Module 1.2.2.4
Drupal Drupal Pubcookie Module 1.6.2.1
7.5
CVSSv2
CVE-2006-4107
SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote malicious users to execute arbitrary SQL commands via a job or resume search.
Drupal Job Search 4.6 Rev1.3.2
7.5
CVSSv2
CVE-2006-4108
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Drupal Bibliography Module
7.5
CVSSv2
CVE-2006-2831
Drupal 4.6.x prior to 4.6.8 and 4.7.x prior to 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote malicious users to execute arbitrary code by uploading a file with multiple extensions, a variant of...
Drupal Drupal 4.6.0
Drupal Drupal 4.6.1
Drupal Drupal 4.7.1
Drupal Drupal 4.6
Drupal Drupal 4.6.6
Drupal Drupal 4.6.7
Drupal Drupal 4.7.0
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.6.5
7.5
CVSSv2
CVE-2006-2742
SQL injection vulnerability in Drupal 4.6.x prior to 4.6.7 and 4.7.0 allows remote malicious users to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
Drupal Drupal 4.6.5
Drupal Drupal 4.6.6
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.6
Drupal Drupal 4.6.0
Drupal Drupal 4.7.0
Drupal Drupal 4.6.1
Drupal Drupal 4.6.2
6.8
CVSSv2
CVE-2007-6752
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and previous versions allows remote malicious users to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by...
Drupal Drupal 4.6.0
Drupal Drupal 4.6
Drupal Drupal 7.0
Drupal Drupal 5.10
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 6.0
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 6.2
Drupal Drupal 5.17
Drupal Drupal 4.6.9
Drupal Drupal 5.13
Drupal Drupal 6.14
Drupal Drupal 6.24
Drupal Drupal 6.13
Drupal Drupal 4.5.0
Drupal Drupal 5.12
Drupal Drupal 6.18
Drupal Drupal 5.2
Drupal Drupal 7.3
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »