
CVE-2006-3570
https://notcve.org/view.php?id=CVE-2006-3570
13 Jul 2006 — Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo webform de Drupal 4.6 anterior al 8 de Julio de 2006 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de vectores no especificados. • http://drupal.org/node/72846 •

CVE-2006-2831 – Debian Linux Security Advisory 1125-1
https://notcve.org/view.php?id=CVE-2006-2831
06 Jun 2006 — Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743. Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web scripts. • http://drupal.org/files/sa-2006-007/advisory.txt •

CVE-2006-2832 – Debian Linux Security Advisory 1125-1
https://notcve.org/view.php?id=CVE-2006-2832
06 Jun 2006 — Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename. Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web scripts. • http://drupal.org/files/sa-2006-007/advisory.txt •

CVE-2006-2833 – Debian Linux Security Advisory 1125-1
https://notcve.org/view.php?id=CVE-2006-2833
06 Jun 2006 — Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable. Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web scripts. • http://drupal.org/files/sa-2006-008/4.6.7.patch •

CVE-2006-2742 – Debian Linux Security Advisory 1125-1
https://notcve.org/view.php?id=CVE-2006-2742
01 Jun 2006 — SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc. Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web scripts. • http://drupal.org/node/65357 •

CVE-2006-2743 – Drupal 4.7 - 'Attachment mod_mime' Remote Command Execution
https://notcve.org/view.php?id=CVE-2006-2743
01 Jun 2006 — Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory. Several remote vulnerabilities have been discovered in the Drupal web site platform, which may lead to the execution of arbitrary web scripts. • https://www.exploit-db.com/exploits/1821 •