3 results (0.002 seconds)

CVSS: 2.1EPSS: 0%CPEs: 13EXPL: 0

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "the vocabulary's help text." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo Hierarchical Select v6.x-3.x anterior a v6.x-3.8 para Drupal, permite a usuarios autenticados remotamente con permisos de administración sobre la taxonomía, inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados relativos al "the vocabulary's help text". • http://drupal.org/node/1461318 http://drupal.org/node/1461724 http://drupalcode.org/project/hierarchical_select.git/commit/be32dceb17d25553e474c295a8c3db69eab95cee http://osvdb.org/79683 http://secunia.com/advisories/48235 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52228 https://exchange.xforce.ibmcloud.com/vulnerabilities/73611 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 2.6EPSS: 0%CPEs: 3EXPL: 0

The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php. El módulo CDN v6.x-2.2 y v7.x-2.2 para Drupal, cuando está en ejecución en modo Origin Pull con la opción "Far Future expiration" habilitada, permite a atacantes remotos leer ficheros PHP de su elección a través de vectores no especificados, como se ha demostrado leyendo settings.php. • http://drupal.org/node/1441480 http://drupal.org/node/1441482 http://drupalcode.org/project/cdn.git/commitdiff/cd2a5ff http://drupalcode.org/project/cdn.git/commitdiff/eca85e6 http://secunia.com/advisories/48032 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/79317 https://drupal.org/node/1441502 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 2.1EPSS: 0%CPEs: 33EXPL: 0

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo Hierarchical Select 5.x en versiones anteriores a la 5.x-3.2 y 6.x en versiones anteriores a la 6.x-3.2 para Drupal, permite a atacantes remotos autenticados, con permisos de administrador "taxonomy", inyectar secuencias de comandos web o HTML de su elección mediante vectores no especificados el el formulario hierarchical_select. • http://drupal.org/node/847488 http://osvdb.org/66117 http://secunia.com/advisories/40440 http://www.securityfocus.com/bid/41450 https://exchange.xforce.ibmcloud.com/vulnerabilities/60158 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •