CVE-2012-4498
https://notcve.org/view.php?id=CVE-2012-4498
The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restrictions and possibly have other unspecified impact. El módulo Activism v6.x-2.x antes de v6.x-2.1 para Drupal no restringe adecuadamente el acceso al tipo de contenido "Campaña", lo que podría permitir a atacantes remotos evitar las restricciones de acceso y posiblemente tener un impacto no especificado. • http://drupal.org/node/1762152 http://drupal.org/node/1762160 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-4487
https://notcve.org/view.php?id=CVE-2012-4487
The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created. El módulo Subuser antes de v6.x-1.8 para Drupal no comprueba correctamente los permisos "switch subuser", lo que permite cambiar su rol a usuarios remotos autenticados por el de un subusuario que éste haya creado. • http://drupal.org/node/1700550 http://drupal.org/node/1700584 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-5704
https://notcve.org/view.php?id=CVE-2012-5704
The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a block that references itself. El módulo Hotblocks v6.x-1.x antes de v6.x-1.8 para Drupal permite a usuarios remotos autenticados y con permiso "administrar hotblocks" causar una denegación de servicio (bucle infinito y timeout) a través de un bloque que hace referencia a sí mismo. • http://drupal.org/node/1732828 http://drupal.org/node/1732946 http://www.madirish.net/543 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-399: Resource Management Errors •
CVE-2012-5705
https://notcve.org/view.php?id=CVE-2012-5705
Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en la página de ajustes (admin/settings/hotblocks) en el módulo Hotblocks v6.x-1.x antes de v6.x-1.8 para Drupal, permite a usuarios remotos autenticados con el permiso "administrar hotblocks" inyectar secuencias de comandos web o HTML a través de "nombres de bloque". • http://drupal.org/node/1732828 http://drupal.org/node/1732946 http://www.madirish.net/543 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-4495
https://notcve.org/view.php?id=CVE-2012-4495
The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments. El módulo Mime Mail v6.x-1.x antes de v6.x-1.1 para Drupal no restringe correctamente el acceso a archivos fuera de los directorios de archivos publicados de Drupal, lo que permite a usuarios autenticados remotamente enviar archivos arbitrarios como adjuntos. • http://drupal.org/node/1719446 http://drupal.org/node/1719482 http://drupalcode.org/project/mimemail.git/commitdiff/ae065d1 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 http://www.securityfocus.com/bid/54914 • CWE-264: Permissions, Privileges, and Access Controls •