Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 5.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-3744
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x prior to 5.10 and 6.x prior to 6.4 allow remote malicious users to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.
Drupal Drupal 5.4
Drupal Drupal 6.2
Drupal Drupal 5.2
Drupal Drupal 5.7
Drupal Drupal 5.0
Drupal Drupal 6.1
Drupal Drupal 5.6
Drupal Drupal 5.1
Drupal Drupal 5.5
Drupal Drupal 6.0
Drupal Drupal 5.9
Drupal Drupal 5.8
Drupal Drupal 5.3
Drupal Drupal 6.3
NA
CVE-2008-2999
Multiple SQL injection vulnerabilities in the Aggregation module 5.x prior to 5.x-4.4 for Drupal allow remote malicious users to execute arbitrary SQL commands via unspecified vectors.
Drupal Drupal 5.4
Drupal Aggregation Module 3.2
Drupal Drupal 5.2
Drupal Drupal 5.7
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 5.0
Drupal Aggregation Module 4.0
Drupal Aggregation Module 4.1
Drupal Aggregation Module 4.3
Drupal Aggregation Module 4.2
Drupal Drupal 5.1
Drupal Drupal 5.3
Drupal Aggregation Module 3.1
Drupal Drupal 5.5.
Drupal Aggregation Module 3.0
NA
CVE-2008-0276
Cross-site scripting (XSS) vulnerability in the Devel module prior to 5.x-0.1 for Drupal allows remote malicious users to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.
Drupal Drupal 4.6
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.4
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.10
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
NA
CVE-2008-0272
Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x prior to 4.7.11 and 5.x prior to 5.6 allows remote malicious users to delete items from a feed as privileged users.
Drupal Drupal 4.6
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.4
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.10
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
NA
CVE-2008-0273
Interpretation conflict in Drupal 4.7.x prior to 4.7.11 and 5.x prior to 5.6, when Internet Explorer 6 is used, allows remote malicious users to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML fil...
Drupal Drupal 4.6
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.4
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.10
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
NA
CVE-2007-6299
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x prior to 4.7.9 and 5.x prior to 5.4 allow remote malicious users to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ...
Drupal Drupal 4.6.0
Drupal Drupal 4.6
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 4.6.9
Drupal Drupal 5.2
Drupal Drupal 4.5.2
Drupal Drupal 4.7.5
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 4.7.8
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 5.0
Drupal Drupal 4.4.2
Drupal Drupal 4.6.3
Drupal Drupal 4.5.8
NA
CVE-2007-5621
Multiple cross-site scripting (XSS) vulnerabilities in the Token module prior to 4.7.x-1.5, and 5.x prior to 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote auth...
Drupal Invite Module
Drupal Token Module
Drupal Drupal 5.2
Drupal Paypal Node Module
Drupal Node Relativity Module
Drupal Ubercart Module
Drupal Drupal 5.0
Drupal Pathauto Module
Drupal Drupal 4.7
Drupal E-commerce Module
Drupal Drupal 5.1
Drupal Asin Field Module
Drupal Fullname Field For Cck
NA
CVE-2007-4063
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x prior to 5.2 allow remote malicious users to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.
Drupal Drupal 5.1 Rev1.1
Drupal Drupal 5.0
Drupal Drupal 5.1
NA
CVE-2007-4064
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x prior to 5.2, and 4.7.x prior to 4.7.7, (1) allow remote malicious users to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administ...
Drupal Drupal 4.7.2
Drupal Drupal 4.7.5
Drupal Drupal 4.7.3
Drupal Drupal 5.0
Drupal Drupal 4.7.0
Drupal Drupal 4.7 Rev1.15
Drupal Drupal 4.7
Drupal Drupal 4.7.6
Drupal Drupal 5.1
Drupal Drupal 4.7.4
Drupal Drupal 4.7.1
NA
CVE-2007-1360
Unspecified vulnerability in the Nodefamily module for Drupal 5.x prior to 5.x-1.0 allows remote authenticated users to access and modify other users' profiles via unspecified URL parameters.
Drupal Nodefamily 5.1 1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-6267
XML injection
CVE-2024-37673
CVE-2024-6266
CVE-2024-30078
arbitrary
CVE-2024-36886
CVE-2024-5346
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »