CVE-2008-6171
https://notcve.org/view.php?id=CVE-2008-6171
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header. El archivo includes/bootstrap.inc en Drupal versiones 5.x anterior a 5.12 y versiones 6.x anterior a 6.6, cuando el servidor está configurado para "IP-based virtual hosts," permite a los atacantes remotos incluir y ejecutar archivos arbitrarios por medio del encabezado Host de HTTP. • http://drupal.org/files/sa-2008-067/SA-2008-067-5.11.patch http://drupal.org/node/324824 http://secunia.com/advisories/32389 http://secunia.com/advisories/32441 http://www.securityfocus.com/bid/31900 http://www.vupen.com/english/advisories/2008/2913 https://exchange.xforce.ibmcloud.com/vulnerabilities/46049 https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00783.html https://www.redhat.com/archives/fedora-package-announce/2008-October/msg00826.html • CWE-16: Configuration CWE-20: Improper Input Validation •
CVE-2008-6160
https://notcve.org/view.php?id=CVE-2008-6160
Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors. Semantically-Interconnected Online Communities (SIOC) 5.x antes de 5.x-1.2 y 6.x antes de 6.x-1.1, un módulo de Drupal, no implementa de manera apropiada las APIs menu y database, lo que permite a atacantes remotos obtener nombres de usuarios y leer el resumen digital (hashed) de correos electrónicos y comentarios mediante vectores no especificados. • http://drupal.org/node/318749 http://secunia.com/advisories/32191 http://www.securityfocus.com/bid/31658 https://exchange.xforce.ibmcloud.com/vulnerabilities/45762 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2009-0603
https://notcve.org/view.php?id=CVE-2009-0603
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information. Una vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados(XSS) en index.php en el módulo Link 5.x-2.5 para Drupal 5.10 permite inyectar, a los usuarios remotos autenticados (con privilegios para "administrar los tipos de contenido"), HTML o scripts Web arbitrarios a través del parámetro descripción (alias el campo Help). NOTA: Algunos de estos detalles se obtienen a partir de información de terceros. • http://archives.neohapsis.com/archives/fulldisclosure/2009-02/0036.html http://osvdb.org/51780 http://secunia.com/advisories/33835 http://www.securityfocus.com/bid/33642 https://exchange.xforce.ibmcloud.com/vulnerabilities/48553 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2008-6137
https://notcve.org/view.php?id=CVE-2008-6137
EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors. EveryBlog v5.x y v6.x, un modulo para Drupal, permite a atacantes remotos saltarse las restricciones de acceso mediante vectores no especificados. • http://drupal.org/node/318746 http://secunia.com/advisories/32194 http://www.securityfocus.com/bid/31656 https://exchange.xforce.ibmcloud.com/vulnerabilities/45759 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2008-6135
https://notcve.org/view.php?id=CVE-2008-6135
Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en EveryBlog v5.x y v6.x, un modulo para Drupal, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores no especificados. • http://drupal.org/node/318746 http://secunia.com/advisories/32194 http://www.securityfocus.com/bid/31656 https://exchange.xforce.ibmcloud.com/vulnerabilities/45757 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •