Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 4.6 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-5477
Drupal 4.6.x prior to 4.6.10 and 4.7.x prior to 4.7.4 allows form submissions to be redirected, which allows remote malicious users to obtain arbitrary form information via a crafted URL.
Drupal Drupal 4.6.0
Drupal Drupal 4.6.5
Drupal Drupal 4.7.2
Drupal Drupal 4.6.9
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.7.0
Drupal Drupal 4.6.7
Drupal Drupal 4.6.1
Drupal Drupal 4.7.1
Drupal Drupal 4.6.6
NA
CVE-2006-4120
Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) prior to 1.54 for Drupal 4.6 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Drupal
Drupal Drupal 4.5.4
Drupal Drupal 4.5.2
Drupal Recipe Module
Drupal Drupal 4.0
Drupal Drupal 4.5.7
Drupal Drupal 4.4.1
Drupal Drupal 4.5.1
Drupal Drupal 4.4.2
Drupal Drupal 4.5.5
Drupal Drupal 4.5
Drupal Drupal 4.5.3
Drupal Drupal 4.4.0
Drupal Drupal 4.5.6
NA
CVE-2006-5476
Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x prior to 4.6.10 and 4.7.x prior to 4.7.4 allows remote malicious users to perform unauthorized actions as an arbitrary user via unspecified vectors.
Drupal Drupal 4.6.0
Drupal Drupal 4.6.5
Drupal Drupal 4.7.2
Drupal Drupal 4.6.9
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.7.0
Drupal Drupal 4.6.7
Drupal Drupal 4.6.1
Drupal Drupal 4.7.1
Drupal Drupal 4.6.6
NA
CVE-2006-5475
Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x prior to 4.6.10 and 4.7.x prior to 4.7.4 allow remote malicious users to inject arbitrary web script or HTML via a crafted RSS feed.
Drupal Drupal 4.6.0
Drupal Drupal 4.6.5
Drupal Drupal 4.7.2
Drupal Drupal 4.6.9
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.7.3
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.7.0
Drupal Drupal 4.6.7
Drupal Drupal 4.6.1
Drupal Drupal 4.7.1
Drupal Drupal 4.6.6
NA
CVE-2007-6752
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and previous versions allows remote malicious users to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by...
Drupal Drupal 4.6.0
Drupal Drupal 4.6
Drupal Drupal 7.0
Drupal Drupal 5.10
Drupal Drupal 5.4
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 6.0
Drupal Drupal 4.7.2
Drupal Drupal 4.6.10
Drupal Drupal 6.2
Drupal Drupal 5.17
Drupal Drupal 4.6.9
Drupal Drupal 5.13
Drupal Drupal 6.14
Drupal Drupal 6.24
Drupal Drupal 6.13
Drupal Drupal 4.5.0
Drupal Drupal 5.12
Drupal Drupal 6.18
Drupal Drupal 5.2
Drupal Drupal 7.3
1 EDB exploit
NA
CVE-2006-4002
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 prior to 4.6.9, and 4.7 prior to 4.7.3, allows remote malicious users to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.
Drupal Drupal 4.6.0
Drupal Drupal 4.6.5
Drupal Drupal 4.7.2
Drupal Drupal 4.6.2
Drupal Drupal 4.6.8
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.7.0
Drupal Drupal 4.6.7
Drupal Drupal 4.6.1
Drupal Drupal 4.7.1
Drupal Drupal 4.6.6
NA
CVE-2006-1227
Drupal 4.5.x prior to 4.5.8 and 4.6.x prior to 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote malicious users to access administrator pages.
Drupal Drupal 4.6.0
Drupal Drupal 4.6.5
Drupal Drupal 4.5.4
Drupal Drupal 4.5.0
Drupal Drupal 4.5.2
Drupal Drupal 4.6.2
Drupal Drupal 4.5.7
Drupal Drupal 4.5.1
Drupal Drupal 4.6.3
Drupal Drupal 4.6.4
Drupal Drupal 4.5.5
Drupal Drupal 4.6.1
Drupal Drupal 4.5.3
Drupal Drupal 4.5.6
NA
CVE-2006-1226
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x prior to 4.5.8 and 4.6.x prior to 4.5.8 allows remote malicious users to inject arbitrary web script or HTML via unknown attack vectors.
Drupal Drupal 4.6.0
Drupal Drupal 4.5.0
Drupal Drupal 4.5.2
Drupal Drupal 4.5.1
Drupal Drupal 4.6.1
Drupal Drupal 4.5.3
NA
CVE-2006-1228
Session fixation vulnerability in Drupal 4.5.x prior to 4.5.8 and 4.6.x prior to 4.5.8 allows remote malicious users to gain privileges by tricking a user to click on a URL that fixes the session identifier.
Drupal Drupal 4.6.0
Drupal Drupal 4.5.0
Drupal Drupal 4.5.2
Drupal Drupal 4.5.1
Drupal Drupal 4.6.1
Drupal Drupal 4.5.3
NA
CVE-2006-1225
CRLF injection vulnerability in Drupal 4.5.x prior to 4.5.8 and 4.6.x prior to 4.5.8 allows remote malicious users to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
Drupal Drupal 4.6.0
Drupal Drupal 4.5.0
Drupal Drupal 4.5.2
Drupal Drupal 4.5.1
Drupal Drupal 4.6.1
Drupal Drupal 4.5.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »