Security

SA-2008-059 - Brilliant Gallery - SQL Injection and Cross Site Scripting

Security announcements - Wed, 2008-10-01 22:24
  • Advisory ID: DRUPAL-SA-2008-059
  • Project: Brilliant Gallery (third-party module)
  • Versions: 5.x
  • Date: 2008-October-1
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection and Cross Site Scripting

read more

Categories: Drupal, Security

SA-2008-058 - Brilliant Gallery - SQL Injection

Security announcements - Thu, 2008-09-25 00:42
  • Advisory ID: DRUPAL-SA-2008-058
  • Project: Brilliant Gallery (third-party module)
  • Versions: 5.x, 6.x
  • Date: 2008-September-25
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection

read more

Categories: Drupal, Security

SA-2008-057 - Ajax Checklist - Multiple vulnerabilities

Security announcements - Wed, 2008-09-24 21:48
  • Advisory ID: DRUPAL-SA-2008-057
  • Project: Ajax Checklist (third-party module)
  • Versions: 5.x
  • Date: 2008-September-24
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection, Cross site scripting

read more

Categories: Drupal, Security

SA-2008-056 - Simplenews - Cross site scripting

Security announcements - Wed, 2008-09-24 20:58
  • Advisory ID: DRUPAL-SA-2008-056
  • Project: Simplenews (third-party module)
  • Versions: 5.x, 6.x
  • Date: 2008-September-24
  • Security risk: Not Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-055 - Stock - Cross site scripting

Security announcements - Wed, 2008-09-24 20:13
  • Advisory ID: DRUPAL-SA-2008-055
  • Project: Stock (third-party module)
  • Versions: 6.x
  • Date: 2008-September-24
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-054 - Plugin Manager - Access bypass

Security announcements - Wed, 2008-09-24 18:54
  • Advisory ID: DRUPAL-SA-2008-054
  • Project: Plugin Manager (third-party module)
  • Versions: 6.x
  • Date: 2008-September-24
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

read more

Categories: Drupal, Security

SA-2008-053 - Answers - Cross site scripting

Security announcements - Thu, 2008-09-18 15:31
  • Advisory ID: DRUPAL-SA-2008-053
  • Project: Answers (third-party module)
  • Versions: 5.x
  • Date: 2008-September-18
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-052 - Link To Us - Cross site scripting

Security announcements - Wed, 2008-09-17 21:13
  • Advisory ID: DRUPAL-SA-2008-052
  • Project: Link To Us (third-party module)
  • Versions: 5.x
  • Date: 2008-September-17
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-051 - Mailsave - Cross site scripting

Security announcements - Wed, 2008-09-17 19:20
  • Advisory ID: DRUPAL-SA-2008-051
  • Project: Mailsave (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-September-17
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-050 - Mailhandler - SQL injection

Security announcements - Wed, 2008-09-17 18:31
  • Advisory ID: DRUPAL-SA-2008-050
  • Project: Mailhandler (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-September-17
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection

read more

Categories: Drupal, Security

SA-2008-049 - Talk - Multiple vulnerabilities

Security announcements - Wed, 2008-09-17 18:11
  • Advisory ID: DRUPAL-SA-2008-049
  • Project: Talk (third-party module)
  • Version: 5.x, 6.x
  • Date: 2008-September-17
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting, Node access bypass

read more

Categories: Drupal, Security

SA-2008-048-b - CCK - Cross site scripting

Security announcements - Thu, 2008-09-04 21:43
  • Advisory ID: DRUPAL-SA-2008-048-b
  • Project: CCK (third-party module)
  • Version: 5.x
  • Date: 2008-Sep-04
  • Security risk: Not critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-047 - Drupal core - Multiple vulnerabilities

Security announcements - Thu, 2008-08-14 01:27
  • Advisory ID: DRUPAL-SA-2008-047
  • Project: Drupal core
  • Version: 5.x, 6.x
  • Date: 2008-August-13
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

read more

Categories: Drupal, Security

SA-2008-046 - Drupal core - Session fixation

Security announcements - Wed, 2008-07-23 21:58
  • Advisory ID: DRUPAL-SA-2008-046
  • Project: Drupal core
  • Version: 5.x
  • Date: 2008-July-23
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Session fixation

read more

Categories: Drupal, Security

SA-2008-045 - OpenID - Multiple vulnerabilities

Security announcements - Thu, 2008-07-10 00:08
  • Advisory ID: DRUPAL-SA-2008-045
  • Project: OpenID (third-party module)
  • Version: 5.x
  • Date: 2008-July-9
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting, Cross site request forgeries

read more

Categories: Drupal, Security

SA-2008-044 - Drupal core - Multiple vulnerabilities

Security announcements - Wed, 2008-07-09 23:24
  • Advisory ID: DRUPAL-SA-2008-044
  • Project: Drupal core
  • Version: 5x, 6.x
  • Date: 2008-July-9
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

read more

Categories: Drupal, Security

SA-2008-043 - Outline designer - Privilege escalation

Security announcements - Wed, 2008-07-02 22:56
  • Advisory ID: DRUPAL-SA-2008-043
  • Project: Outline designer (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Privilege escalation

read more

Categories: Drupal, Security

SA-2008-042 - Tinytax - Cross site scripting

Security announcements - Wed, 2008-07-02 22:51
  • Advisory ID: DRUPAL-SA-2008-042
  • Project: Tinytax taxonomy block (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: Drupal, Security

SA-2008-041 - Taxonomy autotagger - Multiple vulnerabilities

Security announcements - Wed, 2008-07-02 22:48
  • Advisory ID: DRUPAL-SA-2008-041
  • Project: Taxonomy autotagger (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting and SQL injection

read more

Categories: Drupal, Security

SA-2008-040 - Organic Groups - Cross site scripting and information disclosure

Security announcements - Wed, 2008-07-02 22:42
  • Advisory ID: DRUPAL-SA-2008-040
  • Project: Organic Groups (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-July-02
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting and information disclosure

read more

Categories: Drupal, Security
Syndicate content