3

SA-CONTRIB-2012-018 - Revisioning - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-018
  • Project: Revisioning (third-party module)
  • Version: 6.x
  • Date: 2012-FEB-08
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Drupal Revisioning module (https://drupal.org/project/r

Read more »
Created by group42 5 hours 57 min ago
Category: Security   Tags:
3

SA-CONTRIB-2012-017 - Finder - Multiple vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-017
  • Project: Finder (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-February-08
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Arbitrary PHP code execution, Multiple vulnerabilities

Description

Finder is a Drupal module that allows users to create faceted search forms.

Read more »
Created by david_normaan 1 day 7 min ago
Category: Security   Tags:
3

SA-CONTRIB-2012-016 - Forward module XSS and Access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-016
  • Project: Forward (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-February-01
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, Cross Site Request Forgery

Description

The Forward module enables you to add a "forward this page" link to each node.

Read more »
Created by drupalcoder 1 week 20 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-014 - Drupal Commerce - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-014
  • Project: Drupal Commerce (third-party module)
  • Version: 7.x
  • Date: 2012-January-25
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

Drupal Commerce is a flexible eCommerce framework built on Drupal 7 that lets you construct any type of eCommerce website.

Read more »
Created by Dplanet 2 weeks 15 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2012-015 - Managesite - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-015
  • Project: Managesite (third-party module)
  • Version: 6.x
  • Date: 2012-January-25
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

This module provides a way to build a control panel similar to the one provided by Drupal 7 on the admin zone (/admin).

Read more »
Created by twobits 2 weeks 15 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-013 - Search Autocomplete - SQL Injection

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-013
  • Project: Search Autocomplete (third-party module)
  • Version: 7.x
  • Date: 2012-January-25
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

Description

The Search Autocomplete module allows you to add autocomplete functionality to the search fields of a Drupal site.

Read more »
Created by Angie 2 weeks 15 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-009 - Revisioning - Access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-009
  • Project: Revisioning (third-party module)
  • Version: 7.x
  • Date: 2012-January-18
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

This module enables you to create moderation publication workflows, allowing authors to create content that isn't visible to the public until it has been approved by a moder

Read more »
Created by emmajane 3 weeks 11 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2012-012 - Quicktabs - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-012
  • Project: Quick Tabs (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-January-18
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Quick Tabs module allows users to create blocks of tabbed content, specifying a title for the block and the individual tabs.

Read more »
Created by Angie 3 weeks 11 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-011 - Panels - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-011
  • Project: Panels (third-party module)
  • Version: 6.x
  • Date: 2012-January-18
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Panels module allows a site administrator to create customized layouts for multiple uses.

Read more »
Created by aaron 3 weeks 11 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-010 - stickynote - Multiple vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-010
  • Project: stickynote (third-party module)
  • Version: 7.x
  • Date: 2012-January-17
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery

Description

This module enables you to add textual notes in a block to perform quality assurance of your site.

Read more »
Created by emmajane 3 weeks 11 hours ago
Category: Security   Tags:
2

PSA-2012-001 - Hash DOS attack prevention with Suhosin needs a .htaccess edit

http://drupal.org
  • Advisory ID: DRUPAL-PSA-2012-001
  • Project: Drupal core
  • Version: 6.x, 7.x
  • Date: 2012-01-11
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Denial of Service

Description

PHP is vulnerable to a hash collision denial of service (DOS) attack.

Read more »
Created by aaron 3 weeks 3 days ago
Category: Security   Tags:
3

SA-CONTRIB-2012-008 - Video Filter - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-008
  • Project: Video Filter (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-JANUARY-11
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Video Filter module lets you display videos from various third party sources.

Read more »
Created by group42 4 weeks 7 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2012-004 - Date - SQL injection

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-004
  • Project: Date (third-party module)
  • Version: 6.x
  • Date: 2012-January-11
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

Description

This module enables you to add and administer date fields to nodes. It includes Date Tools, that allows users to convert nodes created with the Event module into Date fields.

Read more »
Created by Angie 4 weeks 7 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2012-007 - Password Policy - Multiple vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-007
  • Project: Password policy (third-party module)
  • Version: 6.x
  • Date: 2012-January-11
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery

Description

This module enables you to specify a certain level of password complexity (aka.

Read more »
Created by addision 4 weeks 7 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-006 XSS and CSRF in Multiple Modules - Supercron, Taxotouch, Admin:hover, Taxonomy Navigator no longer supported

http://drupal.org Read more »
Created by david_normaan 4 weeks 7 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-005 - Vote up/down - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-005
  • Project: Vote Up/Down (third-party module)
  • Version: 6.x
  • Date: 2012-January-11
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

This module enables you to add voting widgets to nodes, terms and comments.

Read more »
Created by drupalcoder 4 weeks 7 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2012-003 - Fill PDF - Multiple Vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-003
  • Project: Fill PDF (third-party module)
  • Version: 6.x, 7.x
  • Date: 2012-JANUARY-04
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, Arbitrary code execution

Description

This module enables you to populate fillable PDF templates with data from nodes and webforms.

Read more »
Created by fourkitchens 5 weeks 20 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2012-002 - Lingotek - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-002
  • Project: Lingotek Collaborative Translation (third-party module)
  • Version: 6.x
  • Date: 2012-January-04
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

This module enables you to translate a website's content using tools provided by the Lingotek Collaborative Translation Network.

Read more »
Created by aaron 5 weeks 20 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2012-001 - Registration Codes - Access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2012-001
  • Project: Registration Codes (third-party module)
  • Version: 6.x
  • Date: 2012-January-04
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

The Registration Codes module enables site administrators to restrict registration for new accounts to only users who provide a valid registration code.

Read more »
Created by fourkitchens 5 weeks 20 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-059 - Meta tags quick - Cross Site Scripting (XSS)

http://drupal.org

Description

The Meta tags quick module provides a simple tool to add meta tags to a site. The module doesn't consistently filter user input which could lead to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer content types", "administer vocabularies and terms" or another permission that allows modifying the names of entity bundles.

Read more »
Created by development_seed 8 weeks 1 day ago
Category: Security   Tags:
4

SA-CONTRIB-2011-058 - Support Timer - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-058
  • Project: Support Timer (third-party module)
  • Version: 6.x
  • Date: 2011-November-30
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Support Timer module adds a javascript-based timer to the Support Ticketing System for t

Read more »
Created by drupalcoder 10 weeks 16 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-056 - Webform Validation Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-056
  • Project: Webform Validation (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-November-30
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Webform Validation module enables you to add form validation rules to Webform components through a UI.

Read more »
Created by fourkitchens 10 weeks 16 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-057 - Support Ticketing System - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-057
  • Project: Support Ticketing System (third-party module)
  • Version: 6.x
  • Date: 2011-November-30
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Support Ticketing System module provides a basic ticketing system and helpdesk that is native to Drupal, offering complete email integration.

Read more »
Created by david_normaan 10 weeks 16 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-037- Node Invite - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-037
  • Project: Node Invite (third-party module)
  • Version: 6.x
  • Date: 2011-August-31
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Node Invite module allows you to invite users (with existing accounts or otherwise) to specified nodes on a Drupal site.

Read more »
Created by group42 11 weeks 5 days ago
Category: Security   Tags:
2

SA-CONTRIB-2011-033 - iWebkit - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-033
  • Project: iWebkit (third-party module)
  • Version: 6.x
  • Date: 2011-August-03
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

iWebKit is a web toolkit designed to create iPhone and iPod touch compatible websites and webapps.

Read more »
Created by aaron 11 weeks 6 days ago
Category: Security   Tags:
3

SA-CONTRIB-2011-054 - CKEditor - Access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-054
  • Project: CKEditor - WYSIWYG HTML editor (third-party module)
  • Version: 7.x
  • Date: 2011-November-09
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

The CKEditor module allows Drupal to replace textarea fields with the CKEditor - a visual HTML editor, sometimes called WYSIWYG editor.

Read more »
Created by civiactions 13 weeks 21 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-053 - Quiz - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-053
  • Project: Quiz (third-party module)
  • Version: 6.x
  • Date: 2011-November-09
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

Quiz module allows the creation and taking of tests that are scored either automatically or manually by a teacher.

Read more »
Created by group42 13 weeks 21 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-055 - Webform CiviCRM Integration - Multiple vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-055
  • Project: Webform CiviCRM Integration (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-November-09
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, SQL Injection

Description

The Webform CiviCRM Integration module extends the functionality of the

Read more »
Created by development_seed 13 weeks 21 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-051 - Hotblocks module - multiple vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-051
  • Project: HotBlocks (third-party module)
  • Version: 6.x
  • Date: 2011-November-02
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass, Cross Site Scripting, Cross Site Request Forgery

Description

The HotBlocks module provides a rich experience for managing blocks.

Read more »
Created by drupalcoder 14 weeks 16 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-052 - Views SQL Injection

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-052
  • Project: Views (third-party module)
  • Version: 6.x
  • Date: 2011-November-02
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

Description

The Views module enables you to list content in your site in various ways.

Read more »
Created by twobits 14 weeks 16 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-050 - Organic groups - Access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-050
  • Project: Organic groups (third-party module)
  • Version: 7.x
  • Date: 2011-October-26
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

Organic groups (OG) enables users to create and manage their own 'groups'.

Read more »
Created by david_normaan 15 weeks 12 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-048 - Certificate Login SQL Injection

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-048
  • Project: Certificate Login (third-party module)
  • Version: 5.x, 6.x
  • Date: 2011-October-12
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

Description

The Certificate login module provides client certificate authentication of Drupal users.

Read more »
Created by david_normaan 17 weeks 21 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-049 - Cumulus - Cross Site Scripting (XSS)

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-049
  • Project: Cumulus (third-party module)
  • Version: 5.x, 6.x
  • Date: 2011-October-12
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting (XSS)

Description

The Cumulus module allows you to display your site's tags using a 3D Flash animation.

Read more »
Created by aaron 17 weeks 21 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-044 - Homebox for Organic Groups Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-044
  • Project: Homebox (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-October-05
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting (XSS)

Description

Homebox allows site administrators to create dashboards for their users, using

Read more »
Created by dries 18 weeks 16 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-045 - Rate module Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-045
  • Project: Rate (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-October-05
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting (XSS)

Description

The Rate module provides flexible rate widgets.

Read more »
Created by civiactions 18 weeks 16 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-043 - Petition Node - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-043
  • Project: petition_node (third-party module)
  • Version: 6.x
  • Date: 2011-October-05
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

Petition node module allows the creation of petition nodes to collect signatures to show support for a cause.

Read more »
Created by group42 18 weeks 16 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-046 - Echo - Multiple Vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-046
  • Project: Echo (third-party module)
  • Version: 6.x, 7.x, 8.x
  • Date: 2011-October-05
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

Description

The Echo module generates a fully-themed Drupal page, returning the rendered page as a text string and allowing other modules to style an HTML message as if it had been ge

Read more »
Created by dries 18 weeks 16 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-047 - OG Features access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-047
  • Project: OG Features (third-party module)
  • Version: 6.x
  • Date: 2011-October-05
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

OG Features provides a mechanism for groups to enable or disable certain bundles of functionality, of features, within the groups they administer.

Read more »
Created by development_seed 18 weeks 16 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-042 Views Bulk Operations - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-042
  • Project: Views Bulk Operations (VBO) (third-party module)
  • Version: 6.x
  • Date: 2011-September-21
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Views Bulk Operations (VBO) module allows actions and rules to be run on the selected views rows (nodes, terms, user, etc).

Read more »
Created by group42 20 weeks 7 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-041 - Hostmaster (Aegir) - Cross Site Scripting

http://drupal.org
  • Advisory ID: SA-CONTRIB-2011-041
  • Project: Hostmaster (Aegir) (third-party module)
  • Version: 6.x
  • Date: 2011-September-21
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

Hostmaster (Aegir) provides a system for managing Drupal sites.

Read more »
Created by drupalcoder 20 weeks 1 day ago
Category: Security   Tags:
4

SA-CONTRIB-2011-040 Author Pane access bypass

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-040
  • Project: Author Pane (third-party module)
  • Version: 6.x
  • Date: 2011-September-7
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

The Author Pane module provides information about users on a site.

Read more »
Created by emmajane 22 weeks 17 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-034 - Display Suite - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-034
  • Project: Display suite (third-party module)
  • Version: 7.x
  • Date: 2011-August-03
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

Display Suite allows you to take full control over how your content is displayed using a drag and drop interface. Arrange your nodes, views, comments, user data etc.

Read more »
Created by twobits 22 weeks 5 days ago
Category: Security   Tags:
3

SA-CONTRIB-2011-032 - Mail Logger - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-032
  • Project: Mail Logger (third-party module)
  • Version: 6.x
  • Date: 2011-August-03
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Mail Logger module logs all outgoing e-mails and provides users with the "access mail logger" permission to view logged e-mails.

Read more »
Created by dries 22 weeks 5 days ago
Category: Security   Tags:
2

SA-CONTRIB-2011-039 - Bot Alarm - Multiple vulnerabilities

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-039
  • Project: Bot Alarm (third-party module)
  • Version: 6.x
  • Date: 2011-August-31
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery

Description

This module enables you to set alarms for your IRC bot.

Read more »
Created by addision 23 weeks 12 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-038 - Taxonomy Views Integrator - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-038
  • Project: Taxonomy Views Integrator (third-party module)
  • Version: 6.x
  • Date: 2011-Augest-31
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

This module enables you to override whole vocabularies or individual terms with the View of your choice.

Read more »
Created by Dplanet 23 weeks 12 hours ago
Category: Security   Tags:
2

SA-CONTRIB-2011-035 Forward module - Open redirect

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-035
  • Project: Forward (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-August-17
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Open redirect

Description

The Forward module enables you to add a "forward this page" link to each node.

Read more »
Created by dries 25 weeks 21 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-036 - Addresses - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-036
  • Project: Addresses (third-party module)
  • Version: 6.x
  • Date: 2011-August-17
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

This module enables you to link your users and contents to physical addresses.
The module doesn't sufficiently filter output when displaying an address.

Read more »
Created by addision 25 weeks 21 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-029 - Taxonomy Filter - Cross Site Scripting

http://drupal.org
  • Advisory ID: DRUPAL-SA-CONTRIB-2011-029
  • Project: Taxonomy Filter (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-July-20
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Description

The Taxonomy Filter module enables users to filter taxonomy listings to find content tagged by multiple terms.

Read more »
Created by addision 29 weeks 21 hours ago
Category: Security   Tags:
3

SA-CONTRIB-2011-031 - SunMailer - Access bypass

http://drupal.org
  • Advisory ID: SA-CONTRIB-2011-31
  • Project: SunMailer Newsletter (third-party module)
  • Version: 6.x
  • Date: 2011-July-20
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Description

SunMailer Newsletter creates an email newsletter that users can subscribe to.

Read more »
Created by Dplanet 29 weeks 21 hours ago
Category: Security   Tags:
4

SA-CONTRIB-2011-030 - Devel - Cross Site Request Forgery

http://drupal.org
  • Advisory ID: SA-CONTRIB-2011-030
  • Project: Devel (third-party module)
  • Version: 6.x, 7.x
  • Date: 2011-July-20
  • Security risk: Not critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery

Description

The devel module is designed as a tool to accelerate Drupal software development.

Read more »
Created by aaron 29 weeks 21 hours ago
Category: Security   Tags:

PSD to Drupal Theme

Drupal Development

Module Development

Get an Estimate

Recent comments