|
267231
|
5.9 |
MEDIUM
Network
|
debian drupal
|
debian_linux drupal
|
CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP re…
|
NVD-CWE-Other
|
CVE-2016-3166
|
2024-11-21 11:49 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267232
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a fo…
|
CWE-284
Improper Access Control
|
CVE-2016-3165
|
2024-11-21 11:49 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267233
|
7.4 |
HIGH
Network
|
drupal debian
|
drupal debian_linux
|
Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, rela…
|
NVD-CWE-Other
|
CVE-2016-3164
|
2024-11-21 11:49 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267234
|
7.5 |
HIGH
Network
|
debian drupal
|
debian_linux drupal
|
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
|
CWE-254
7PK - Security Features
|
CVE-2016-3163
|
2024-11-21 11:49 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267235
|
8.1 |
HIGH
Network
|
drupal debian
|
drupal debian_linux
|
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unproces…
|
CWE-284
Improper Access Control
|
CVE-2016-3162
|
2024-11-21 11:49 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267236
|
9.1 |
CRITICAL
Network
|
postgresql
|
postgresql
|
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequent…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3065
|
2024-11-21 11:49 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267237
|
7.3 |
HIGH
Network
|
prepopulate_project
|
prepopulate
|
The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the (1) actions, (2) container, (3) token, (4) password, (5) passw…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3188
|
2024-11-21 11:49 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267238
|
7.3 |
HIGH
Network
|
prepopulate_project
|
prepopulate
|
The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array, and consequently have unspecified impact, via a base64-encoded pp parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3187
|
2024-11-21 11:49 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267239
|
9.8 |
CRITICAL
Network
|
spip
|
spip
|
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and…
|
CWE-94
Code Injection
|
CVE-2016-3154
|
2024-11-21 11:49 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267240
|
9.8 |
CRITICAL
Network
|
debian spip
|
debian_linux spip
|
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
|
CWE-94
Code Injection
|
CVE-2016-3153
|
2024-11-21 11:49 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|