
CVE-2014-9156
https://notcve.org/view.php?id=CVE-2014-9156
01 Dec 2014 — The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file. El módulo FileField 6.x-3.x anterior a 6.x-3.13 para Drupal no comprueba correctamente los permisos para visualizar ficheros, lo que permite a usuarios remotos autenticados crear o editar los contenidos para leer ficheros privados mediante el adjunto de un fichero subid... • http://cgit.drupalcode.org/filefield/commit/?id=3a97fe1 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2010-1958
https://notcve.org/view.php?id=CVE-2010-1958
21 Jun 2010 — Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter). Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo FileField v5.x anteriores a v5.x-2.5 y v6.x anteriores a v6.x-3.4 para Drupal. Permite a usuarios remotos autenticad... • http://drupal.org/node/829808 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •