Page 23 of 402 results (0.004 seconds)

CVSS: 4.0EPSS: 0%CPEs: 10EXPL: 0

The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created. El módulo Subuser antes de v6.x-1.8 para Drupal no comprueba correctamente los permisos "switch subuser", lo que permite cambiar su rol a usuarios remotos autenticados por el de un subusuario que éste haya creado. • http://drupal.org/node/1700550 http://drupal.org/node/1700584 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restrictions and possibly have other unspecified impact. El módulo Activism v6.x-2.x antes de v6.x-2.1 para Drupal no restringe adecuadamente el acceso al tipo de contenido "Campaña", lo que podría permitir a atacantes remotos evitar las restricciones de acceso y posiblemente tener un impacto no especificado. • http://drupal.org/node/1762152 http://drupal.org/node/1762160 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 3.5EPSS: 0%CPEs: 5EXPL: 1

The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a block that references itself. El módulo Hotblocks v6.x-1.x antes de v6.x-1.8 para Drupal permite a usuarios remotos autenticados y con permiso "administrar hotblocks" causar una denegación de servicio (bucle infinito y timeout) a través de un bloque que hace referencia a sí mismo. • http://drupal.org/node/1732828 http://drupal.org/node/1732946 http://www.madirish.net/543 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-399: Resource Management Errors •

CVSS: 2.1EPSS: 0%CPEs: 5EXPL: 1

Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names." Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en la página de ajustes (admin/settings/hotblocks) en el módulo Hotblocks v6.x-1.x antes de v6.x-1.8 para Drupal, permite a usuarios remotos autenticados con el permiso "administrar hotblocks" inyectar secuencias de comandos web o HTML a través de "nombres de bloque". • http://drupal.org/node/1732828 http://drupal.org/node/1732946 http://www.madirish.net/543 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 8EXPL: 0

Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site). Vulnerabilidad Cross-Site Scripting (XSS) en la interfaz administrativa en el módulo Campaign Monitor en versiones anteriores a la 6.x-2.5 para Drupal permite que los atacantes remotos inyecten scripts web o HTML arbitrarios mediante vectores sin especificar. NOTA: esto se refiera a un problema en un módulo de Drupal desarrollado de manera independiente y NO en el software Campaign Monitor (descrito en el sitio web campaignmonitor.com). • http://drupal.org/node/1689790 http://drupal.org/node/1691446 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •