SA-CONTRIB-2010-093 - Advanced Taxonomy Blocks - Multiple Vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-093
  • Project: Advanced Taxonomy Blocks (third-party module)
  • Version: 6.x
  • Date: 2010-September-15
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery

SA-CONTRIB-2010-092 - Advanced Book Blocks - Multiple Vulnerabilities

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-092
  • Project: Advanced Book Blocks (third-party module)
  • Version: 6.x
  • Date: 2010-September-15
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting, Cross Site Request Forgery

SA-CONTRIB-2010-091 - Mollom - Information Disclosure

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-091
  • Project: Mollom (third-party module)
  • Version: 6.x
  • Date: 2010-September-15
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Information Disclosure

SA-CONTRIB-2010-090 - Yr Weatherdata - SQL Injection

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-090
  • Project: Yr Weatherdata (third-party module)
  • Version: 6.x
  • Date: 2010-September-08
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: SQL Injection

SA-CONTRIB-2010-089 - Simplenews Content Selection - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-089
  • Project: Simplenews content selection (third-party module)
  • Version: 6.x
  • Date: 2010-August-18
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

SA-CONTRIB-2010-088 - Content Construction Kit (CCK) - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-088
  • Project: Content Construction Kit (CCK) (third-party module)
  • Version: 6.x
  • Date: 2010-August-11
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

SA-CONTRIB-2010-087 - GovDelivery - Cross site scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-087
  • Project: GovDelivery Integration (third-party module)
  • Version: 6.x
  • Date: 2010-Aug-11
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

SA-CONTRIB-2010-086 - Prepopulate - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-086
  • Project: Prepopulate (third-party module)
  • Version: 5.x and 6.x
  • Date: 2010-Aug-11
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

SA-CONTRIB-2010-085 - Pathauto - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-085
  • Project: Pathauto (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-August-11
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2010-084 - OpenID - Authentication bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-084
  • Project: OpenID (third-party module)
  • Version: 5.x
  • Date: 2010-Aug-11
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Authentication bypass

Pages

Subscribe with RSS Subscribe to Security advisories