CVE-2013-0321
https://notcve.org/view.php?id=CVE-2013-0321
Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field. Vulnerabilidad de e jecución de secuencias de comandos en sitios cruzados(XSS) en Views en el modulo Ubercart Views (uc_views) v6.x módulo antes de v6.x-3.3 para Drupal que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del campo Nombre completo. • http://drupal.org/node/1922128 http://drupal.org/node/1922416 http://drupalcode.org/project/uc_views.git/commitdiff/157d5d3 http://www.openwall.com/lists/oss-security/2013/02/21/5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0257
https://notcve.org/view.php?id=CVE-2013-0257
The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields. El módulo email2image v6.x-1.x y v6.x-2.x para Drupal no restringe debidamente el acceso a los nodos, lo que permite a atacantes remotos leer las imágenes de las direcciones de correo electrónico del usuario y los campos de correo electrónico. • http://drupal.org/node/1903264 http://www.openwall.com/lists/oss-security/2013/02/05/1 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2013-0320
https://notcve.org/view.php?id=CVE-2013-0320
Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el Administrador de Taxonomía (taxonomy_manager) módulo v6.x-2.x antes v6.x-2.2 y v7.x-1.x antes v7.x-1.0-rc1 para Drupal permite a atacantes remotos secuestrar a la autenticación de usuarios con el permiso 'administer taxonomy' a ??través de vectores no especificados. • http://drupal.org/node/1922168 http://drupal.org/node/1922170 http://drupal.org/node/1922410 http://drupalcode.org/project/taxonomy_manager.git/commitdiff/2d05801 http://drupalcode.org/project/taxonomy_manager.git/commitdiff/595f1b3 http://www.openwall.com/lists/oss-security/2013/02/21/5 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-0325
https://notcve.org/view.php?id=CVE-2013-0325
Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting. Multiples cross-site scripting (XSS) en el modulo Varnish v6.x-1.x anterior a v6.x-1.2 y v7.x-1.x anterior a v7.x-1.0-beta2 para Drupal permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) mensajes Watchdog o (2) configuración del administrador. • http://drupal.org/node/1922726 http://drupal.org/node/1922730 http://drupal.org/node/1922756 http://drupalcode.org/project/varnish.git/commitdiff/e6726b4 http://drupalcode.org/project/varnish.git/commitdiff/f69a62c http://www.openwall.com/lists/oss-security/2013/02/21/5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0225
https://notcve.org/view.php?id=CVE-2013-0225
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo User Relationships v6.x-1.x anterior a v6.x-1.4 y v7.x-1.x anterior a v7.x-1.0-alpha5 para Drupal, permite a usuarios remotos autenticados con el permiso "administrar las relaciones de usuario" inyectar secuencias de comandos web o HTML a través de un nombre de relación. • http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9 http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739 http://www.openwall.com/lists/oss-security/2013/01/25/4 https://drupal.org/node/1896272 https://drupal.org/node/1896276 https://drupal.org/node/1896720 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •