SA-CONTRIB-2011-013 - Tagadelic - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-013
  • Project: Tagadelic (third-party module)
  • Version: 6.x
  • Date: 2011-March-16
  • Security risk: Moderately Critical (definition of risk levels)
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-012 - Spaces - Access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-012
  • Project: Spaces (third-party module)
  • Version: 6.x
  • Date: 2011-March-02
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

SA-CONTRIB-2011-011 - Secure Pages - Open redirect

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-011
  • Project: Secure Pages (third-party module)
  • Version: 6.x
  • Date: 2011-March-02
  • Security risk: Less Critical (definition of risk levels)
  • Exploitable from: Remote
  • Vulnerability: Open Redirection

“Drupal security update” social engineering - PSA-2011-001

Date: 
2011-February-17
  • Advisory ID: PSA-2011-001
  • Project: Drupal core and contrib
  • Versions: All versions
  • Date: 2011-February-17
  • Security risk: Not critical

SA-CONTRIB-2011-010 - Messaging - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-010
  • Project: Messaging (third-party module)
  • Version: 6.x
  • Date: 2011-February-16
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-009 - Droptor - SQL Injection

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-009
  • Project: Droptor (third-party module)
  • Version: 6.x
  • Date: 2011-February-02
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

SA-CONTRIB-2011-008 - Chatroom - Cross Site Scripting (XSS) and Cross Site Request Forgery

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-008
  • Project: Chatroom (third-party module)
  • Version: 6.x
  • Date: 2011-February-02
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting and Cross Site Request Forgery

SA-CONTRIB-2011-007 - Userpoints Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-007
  • Project: Userpoints (third-party module)
  • Version: 6.x
  • Date: 2011-February-02
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-006 - Flag Page - Cross Site Scripting (XSS)

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-006
  • Project: Flag page (third-party module)
  • Version: 6.x
  • Date: 2011-February-02
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2011-005 - AES encryption - Information disclosure

  • Advisory ID: DRUPAL-SA-CONTRIB-2011-005
  • Project: AES (third-party module)
  • Version: 7.x
  • Date: 2011-February-02
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Information Disclosure

Pages

Subscribe with RSS Subscribe to Security advisories