SA-CONTRIB-2013-064 - Persona - Cross site request forgery (CSRF)

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-064
  • Project: Mozilla Persona (third-party module)
  • Version: 7.x
  • Date: 2013-August-07
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery

SA-CONTRIB-2013-063 - Authenticated User Page Caching (Authcache) - Information Disclosure

SA-CONTRIB-2013-062 - RESTful Web Services (RESTWS) - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-062
  • Project: RESTful Web Services (third-party module)
  • Version: 7.x
  • Date: 2013-August-07
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2013-061 - Flippy - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-061
  • Project: Flippy (third-party module)
  • Version: 7.x
  • Date: 2013-July-31
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2013-060 - Scald - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-060
  • Project: Scald (third-party module)
  • Version: 6.x, 7.x
  • Date: 2013-July-24
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2013-059 - Hostmaster (Aegir) - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-059
  • Project: Hostmaster (Aegir) (third-party module)
  • Version: 6.x
  • Date: 2013-July-17
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2013-058 - MRBS - Abandoned - Mutliple vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-058
  • Project: MRBS (third-party module)
  • Version: 6.x, 7.x
  • Date: 2013-July-17
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Request Forgery, SQL Injection

SA-CONTRIB-2013-057 - TinyBox - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-057
  • Project: TinyBox (Simple Splash) (third-party module)
  • Version: 7.x
  • Date: 2013-July-10
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2013-056 - Stage File Proxy - Denial of Service

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-056
  • Project: Stage File Proxy (third-party module)
  • Version: 7.x
  • Date: 2013-July-10th
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

SA-CONTRIB-2013-055 - Hatch - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2013-055
  • Project: Hatch (third-party theme)
  • Version: 7.x
  • Date: 2013-July-10
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Pages

Subscribe with RSS Subscribe to Security advisories