Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 4.7 vulnerabilities and exploits
(subscribe to this query)
605
VMScore
CVE-2006-6646
Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters, which do not use t...
Drupal Drupal Project 4.7
Drupal Drupal Project 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project 4.6
Drupal Drupal Project 4.7 2.0
Drupal Drupal Project 4.6 1.0
445
VMScore
CVE-2007-0658
The (1) Textimage 4.7.x prior to 4.7-1.2 and 5.x prior to 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x prior to 4.7-1.2 and 5.x prior to 5.x-1.1 module for Drupal allow remote malicious users to bypass the CAPTCHA test via an empty captcha element in $_SESSION.
Drupal Drupal 4.7.2
Drupal Textimage 4.7
Drupal Drupal 4.7.5
Drupal Drupal 4.7.3
Drupal Drupal 5.0
Drupal Drupal 4.7 Rev1.15
Drupal Drupal 4.7
Drupal Drupal 4.7.6
Drupal Drupal 5.1
Drupal Drupal 4.7.4
Drupal Drupal 4.7.1
Drupal Textimage 5.0
312
VMScore
CVE-2007-5228
Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module prior to 4.7.x-1.5, 4.7.x-2.x prior to 4.7.x-2.5, and 5.x-1.x prior to 5.x-1.1 for Drupal allows remote authenticated users with project create or edit permissions to i...
Drupal Drupal Project Issue Tracking 4.7 2.1
Drupal Drupal Project Issue Tracking 5.0 0.1
Drupal Drupal Project Issue Tracking 4.7 1.2
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.2
312
VMScore
CVE-2007-1368
The Project issue tracking module prior to 4.7.x-1.3, 4.7.x-2.* prior to 4.7.x-2.3, and 5 prior to 5.x-0.2-beta for Drupal allows remote authenticated users, with "access project issues" permission, to read the contents of a private node via a URL with a modified node i...
Drupal Drupal Project Issue Tracking 4.7 2.1
Drupal Drupal Project Issue Tracking 5.0 0.1
Drupal Drupal Project Issue Tracking 5.7 1.1
Drupal Drupal Project Issue Tracking 4.7 1.2
Drupal Drupal Project Issue Tracking 4.7 2.0
Drupal Drupal Project Issue Tracking 4.7 1.0
Drupal Drupal Project Issue Tracking 4.7 2.2
534
VMScore
CVE-2007-0506
The project_issue_access function in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue informat...
Drupal Project Issue Tracking Module 4.7
Drupal Project 5.0
Drupal Project Issue Tracking Module 5.0
Drupal Project 4.7 2.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.6
Drupal Project 4.7 1.1
Drupal Project 4.6 1.1
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project 4.7
756
VMScore
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project Issue Tracking Module 4.7
Drupal Project 5.0
Drupal Project Issue Tracking Module 5.0
Drupal Project 4.7 2.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.6
Drupal Project 4.7 1.1
Drupal Project 4.6 1.1
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project 4.7
383
VMScore
CVE-2007-4064
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x prior to 5.2, and 4.7.x prior to 4.7.7, (1) allow remote malicious users to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administ...
Drupal Drupal 4.7.2
Drupal Drupal 4.7.5
Drupal Drupal 4.7.3
Drupal Drupal 5.0
Drupal Drupal 4.7.0
Drupal Drupal 4.7 Rev1.15
Drupal Drupal 4.7
Drupal Drupal 4.7.6
Drupal Drupal 5.1
Drupal Drupal 4.7.4
Drupal Drupal 4.7.1
231
VMScore
CVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote malicious users to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
Drupal Drupal 5.0
Drupal Drupal 4.7
383
VMScore
CVE-2006-3570
Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal 4.6
Drupal Drupal 4.7
534
VMScore
CVE-2008-4633
SQL injection vulnerability in Node Vote 5.x prior to 5.x-1.1 and 6.x prior to 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previo...
Drupal Node Clone 4.7.x-1.0
Drupal Node Clone 4.7.x-1.1
Drupal Node Clone 4.7.x-1.2
Drupal Node Clone 4.7.x-1.3
Drupal Node Clone 4.7.x-2.1
Drupal Node Clone 5
Drupal Node Clone 6
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
malicious code
XML injection
CVE-2024-28020
CVE-2024-35252
CVE-2024-5833
CVE-2024-30066
injection
CVE-2024-23282
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »