|
269301
|
- |
|
me_aliases_project
|
me_aliases
|
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in …
|
CWE-284
Improper Access Control
|
CVE-2015-5512
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269302
|
- |
|
hybridauth_social_login_project
|
hybridauth_social_login
|
The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social lo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5511
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269303
|
- |
|
content_construction_kit_project
|
content_construction_kit
|
Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via …
|
NVD-CWE-Other
|
CVE-2015-5510
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269304
|
- |
|
administration_views_project
|
administration_views
|
The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5509
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269305
|
- |
|
the_extensible_catalog_drupal_toolkit_project
|
the_extensible_catalog_drupal_toolkit
|
Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "ad…
|
CWE-352
Origin Validation Error
|
CVE-2015-5508
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269306
|
- |
|
inline_entity_form_project
|
inline_entity_form
|
Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5507
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269307
|
- |
|
apache_solr_real-time_project
|
apache_solr_real-time
|
The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content …
|
CWE-200
Information Exposure
|
CVE-2015-5506
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269308
|
- |
|
codfront_labs
|
http_strict_transport_security
|
The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS pol…
|
CWE-17
Code
|
CVE-2015-5505
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269309
|
- |
|
novalnet
|
novalnet_payment_module_ubercart-
|
SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-5504
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269310
|
- |
|
chamilo_integration_project
|
chamilo_integration
|
Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspe…
|
NVD-CWE-Other
|
CVE-2015-5503
|
2024-11-21 11:33 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|