Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 4.6 vulnerabilities and exploits
(subscribe to this query)
8.5
CVSSv2
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project Issue Tracking Module 4.7
Drupal Project 5.0
Drupal Project Issue Tracking Module 5.0
Drupal Project 4.7 2.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.6
Drupal Project 4.7 1.1
Drupal Project 4.6 1.1
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project 4.7
3.5
CVSSv2
CVE-2007-0124
Unspecified vulnerability in Drupal prior to 4.6.11, and 4.7 prior to 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
Drupal Drupal 4.6.0
Drupal Drupal 4.6
Drupal Drupal 4.6.5
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.7.0
Drupal Drupal 4.6.7
Drupal Drupal 4.7
Drupal Drupal 4.6.1
Drupal Drupal 4.7.4
Drupal Drupal 4.7.1
Drupal Drupal 4.6.6
6
CVSSv2
CVE-2007-0507
SQL injection vulnerability in the Acidfree module for Drupal prior to 4.6.x-1.0, and prior to 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.
Drupal Acidfree 4.6 1.0
Drupal Acidfree 4.7 1.0
4.3
CVSSv2
CVE-2007-2159
Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and prior to 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct d...
Drupal Database Administration Module 4.6
Drupal Database Administration Module 4.7
7.5
CVSSv2
CVE-2007-2160
Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and prior to 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote malicious users to perform unauthorized actions as an arbitrary user, a related issue to CVE-200...
Drupal Database Administration Module 4.6
Drupal Database Administration Module 4.7
7.5
CVSSv2
CVE-2007-6299
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x prior to 4.7.9 and 5.x prior to 5.4 allow remote malicious users to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ...
Drupal Drupal 4.6.0
Drupal Drupal 4.6
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
Drupal Drupal 4.6.3
Drupal Drupal 4.5.8
4.3
CVSSv2
CVE-2008-0273
Interpretation conflict in Drupal 4.7.x prior to 4.7.11 and 5.x prior to 5.6, when Internet Explorer 6 is used, allows remote malicious users to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML fil...
Drupal Drupal 4.6
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.4
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.10
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
4.3
CVSSv2
CVE-2008-0276
Cross-site scripting (XSS) vulnerability in the Devel module prior to 5.x-0.1 for Drupal allows remote malicious users to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.
Drupal Drupal 4.6
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.4
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.10
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
4.3
CVSSv2
CVE-2008-0272
Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x prior to 4.7.11 and 5.x prior to 5.6 allows remote malicious users to delete items from a feed as privileged users.
Drupal Drupal 4.6
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.4
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.10
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
7.5
CVSSv2
CVE-2006-4107
SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote malicious users to execute arbitrary SQL commands via a job or resume search.
Drupal Job Search 4.6 Rev1.3.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
server-side request forgery
CVE-2024-30067
CVE-2024-5553
CVE-2024-30095
IDOR
CVE-2024-35252
CVE-2024-23692
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »