Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 4.6 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-2159
Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and prior to 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct d...
Drupal Database Administration Module 4.6
Drupal Database Administration Module 4.7
NA
CVE-2007-2160
Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and prior to 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote malicious users to perform unauthorized actions as an arbitrary user, a related issue to CVE-200...
Drupal Database Administration Module 4.6
Drupal Database Administration Module 4.7
NA
CVE-2007-0506
The project_issue_access function in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue informat...
Drupal Project 4.6
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
NA
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
Drupal Project 4.6
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
NA
CVE-2007-6299
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x prior to 4.7.9 and 5.x prior to 5.4 allow remote malicious users to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ...
Drupal Drupal 4.4.1
Drupal Drupal 4.4.2
Drupal Drupal 4.5.5
Drupal Drupal 4.5.6
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.7
Drupal Drupal 4.7.1
Drupal Drupal 4.7.8
Drupal Drupal 4.7 Rev1.15
Drupal Drupal 4.2.0 Rc
Drupal Drupal 4.4.0
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.6.1
Drupal Drupal 4.6.10
Drupal Drupal 4.6.11
Drupal Drupal 4.6.8
Drupal Drupal 4.6.9
Drupal Drupal 4.7.6
Drupal Drupal 4.7.7
Drupal Drupal 4.0.0
NA
CVE-2008-0276
Cross-site scripting (XSS) vulnerability in the Devel module prior to 5.x-0.1 for Drupal allows remote malicious users to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.
Drupal Drupal 4.4
Drupal Drupal 4.4.1
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.7
Drupal Drupal 4.7.1
Drupal Drupal 4.7.7
Drupal Drupal 4.7.8
Drupal Drupal 5.3
Drupal Drupal 5.4
Drupal Drupal 4.1.0
Drupal Drupal 4.2.0 Rc
Drupal Drupal 4.5.2
Drupal Drupal 4.5.3
Drupal Drupal 4.6.1
Drupal Drupal 4.6.10
Drupal Drupal 4.6.11
Drupal Drupal 4.6.8
Drupal Drupal 4.6.9
Drupal Drupal 4.7.5
NA
CVE-2008-0272
Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x prior to 4.7.11 and 5.x prior to 5.6 allows remote malicious users to delete items from a feed as privileged users.
Drupal Drupal 4.5
Drupal Drupal 4.5.1
Drupal Drupal 4.5.8
Drupal Drupal 4.6
Drupal Drupal 4.6.5
Drupal Drupal 4.6.6
Drupal Drupal 4.7.3
Drupal Drupal 4.7.4
Drupal Drupal 4.7 Rev 1.2
Drupal Drupal 5.0
Drupal Drupal 4.2.0 Rc
Drupal Drupal 4.4
Drupal Drupal 4.5.4
Drupal Drupal 4.5.5
Drupal Drupal 4.6.11
Drupal Drupal 4.6.2
Drupal Drupal 4.6.9
Drupal Drupal 4.7
Drupal Drupal 4.4.1
Drupal Drupal 4.4.2
Drupal Drupal 4.4.3
Drupal Drupal 4.5.6
NA
CVE-2008-0273
Interpretation conflict in Drupal 4.7.x prior to 4.7.11 and 5.x prior to 5.6, when Internet Explorer 6 is used, allows remote malicious users to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML fil...
Drupal Drupal 4.0.0
Drupal Drupal 4.5.1
Drupal Drupal 4.5.2
Drupal Drupal 4.6
Drupal Drupal 4.6.1
Drupal Drupal 4.6.6
Drupal Drupal 4.6.7
Drupal Drupal 4.6.8
Drupal Drupal 4.7.4
Drupal Drupal 4.7.5
Drupal Drupal 5.0
Drupal Drupal 5.1
Drupal Drupal 4.4.3
Drupal Drupal 4.5
Drupal Drupal 4.5.7
Drupal Drupal 4.5.8
Drupal Drupal 4.6.4
Drupal Drupal 4.6.5
Drupal Drupal 4.7.2
Drupal Drupal 4.7.3
Drupal Drupal 4.7 Rev 1.15
Drupal Drupal 4.7 Rev 1.2
NA
CVE-2006-5477
Drupal 4.6.x prior to 4.6.10 and 4.7.x prior to 4.7.4 allows form submissions to be redirected, which allows remote malicious users to obtain arbitrary form information via a crafted URL.
Drupal Drupal 4.6.6
Drupal Drupal 4.6.7
Drupal Drupal 4.6.8
Drupal Drupal 4.6.2
Drupal Drupal 4.6.3
Drupal Drupal 4.7.1
Drupal Drupal 4.7.2
Drupal Drupal 4.6.4
Drupal Drupal 4.6.5
Drupal Drupal 4.7.3
Drupal Drupal 4.6.0
Drupal Drupal 4.6.1
Drupal Drupal 4.6.9
Drupal Drupal 4.7.0
NA
CVE-2006-4120
Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) prior to 1.54 for Drupal 4.6 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal 4.0
Drupal Drupal 4.4.0
Drupal Drupal 4.4.1
Drupal Drupal 4.5.5
Drupal Drupal 4.5.6
Drupal Drupal 4.5.1
Drupal Drupal 4.5.2
Drupal Recipe Module
Drupal Drupal 4.5.3
Drupal Drupal 4.5.4
Drupal Drupal 4.4.2
Drupal Drupal 4.5
Drupal Drupal 4.5.7
Drupal Drupal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »