Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
drupal drupal 5.x vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-6647
Cross-site scripting (XSS) vulnerability in the MySite 4.7.x prior to 4.7.x-3.3 and 5.x prior to 5.x-1.3 module for Drupal allows remote malicious users to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third par...
Drupal Drupal Mysite 5
Drupal Drupal Mysite 4.7
NA
CVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote malicious users to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
Drupal Drupal 4.7
Drupal Drupal 5.0
NA
CVE-2008-0462
Cross-site scripting (XSS) vulnerability in the Archive 5.x prior to 5.x-1.8 module for Drupal allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Drupal Archive Module
Drupal Drupal
NA
CVE-2008-3000
The Aggregation module 5.x prior to 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows remote malicious users to bypass intended restrictions.
Drupal Aggregation Module 4.0
Drupal Aggregation Module 4.1
Drupal Aggregation Module 5
Drupal Aggregation Module 3.0
Drupal Aggregation Module 3.1
Drupal Aggregation Module 3.2
Drupal Aggregation Module 4.2
Drupal Aggregation Module 4.3
NA
CVE-2008-3001
The Aggregation module 5.x prior to 5.x-4.4 for Drupal allows remote malicious users to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.
Drupal Aggregation Module 3.2
Drupal Aggregation Module 4.0
Drupal Aggregation Module 4.3
Drupal Aggregation Module 5
Drupal Aggregation Module 3.0
Drupal Aggregation Module 3.1
Drupal Aggregation Module 4.1
Drupal Aggregation Module 4.2
NA
CVE-2007-0505
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
Drupal Project 4.6
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
NA
CVE-2008-4633
SQL injection vulnerability in Node Vote 5.x prior to 5.x-1.1 and 6.x prior to 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previo...
Drupal Node Clone 4.7.x-1.3
Drupal Node Clone 4.7.x-2.1
Drupal Node Clone 4.7.x-1.0
Drupal Node Clone 5
Drupal Node Clone 4.7.x-1.2
Drupal Node Clone 4.7.x-1.1
Drupal Node Clone 6
NA
CVE-2007-0506
The project_issue_access function in the Project issue tracking 4.7.0 up to and including 5.x prior to 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue informat...
Drupal Project 4.6
Drupal Project 4.6 1.1
Drupal Project 4.7
Drupal Project Issue Tracking Module 5.0
Drupal Project Issue Tracking Module 4.7 1.1
Drupal Project Issue Tracking Module 4.7 2.1
Drupal Project 4.7 1.1
Drupal Project 4.7 2.1
Drupal Project 5.0
Drupal Project Issue Tracking Module 4.7
NA
CVE-2008-4791
The user module in Drupal 5.x prior to 5.11 and 6.x prior to 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.
Drupal Drupal
6.1
CVSSv3
CVE-2010-2250
Drupal 5.x and 6.x prior to 6.16 uses a user-supplied value in output during site installation which could allow an malicious user to craft a URL and perform a cross-site scripting attack.
Drupal Drupal
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »