CVE-2012-1654
https://notcve.org/view.php?id=CVE-2012-1654
Multiple cross-site scripting (XSS) vulnerabilities in the Data module 6.x-1.x before 6.x-1.0 and 7.x-1.x before 7.x-1.0-alpha3 for Drupal allow remote authenticated users with the administer data tables permission to inject arbitrary web script or HTML via the title parameter in (1) data.views.inc and (2) data_ui/data_ui.admin.inc. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo Data v6.x-1.x antes de v6.x-1.0 y v7.x-1.x antes de v7.x-1.0-alpha3 para Drupal, permite a usuarios autenticados remotamente con permisos de administración de tablas, inyectar secuencias de comandos web o HTML a través del parámetro title en (1) data.views.inc y (2) data_ui/data_ui.admin.inc. • http://drupal.org/node/1470980 http://drupal.org/node/1470982 http://drupal.org/node/1471780 http://drupalcode.org/project/data.git/commit/33f0caa http://drupalcode.org/project/data.git/commit/6f6858a http://secunia.com/advisories/48326 http://www.madirish.net/content/drupal-data-6x-10-xss-vulnerability http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/79854 http://www.securityfocus.com/bid/52337 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-1660
https://notcve.org/view.php?id=CVE-2012-1660
Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en components/select.inc en el módulo Webform v6.x-3.x antes de v6.x-3.17 y v7.x-3.x antes de v7.x-3.17 para Drupal, cuando el módulo "Select (or other)" está habilitado, permite a usuarios autenticados remotamente con permisos de creación de contenidos webform, inyectar secuencias de comandos web o HTML a través de vectores relacionados con (1) casillas de verificación o (2) botones radio. • http://drupal.org/node/1472178 http://drupal.org/node/1472180 http://drupal.org/node/1472214 http://drupalcode.org/project/webform.git/commit/90af819 http://drupalcode.org/project/webform.git/commit/917fa91 http://secunia.com/advisories/48310 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/79852 http://www.securityfocus.com/bid/52345 https://exchange.xforce.ibmcloud.com/vulnerabilities/73779 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-1648
https://notcve.org/view.php?id=CVE-2012-1648
Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo Cool Aid antes de v6.x-1.9 para Drupal permite a usuarios autenticados remotamente con el permiso de administrar coolaid, inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1417186 http://drupal.org/node/1461438 http://osvdb.org/79712 http://secunia.com/advisories/48196 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52232 https://exchange.xforce.ibmcloud.com/vulnerabilities/73607 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-1649
https://notcve.org/view.php?id=CVE-2012-1649
Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors. El módulo Coll Aid antes de v6.x-1.9 para Drupal no impone restricciones de acceso, lo que permite a usuarios remotos autenticados con el permiso de administrar coolaid, modificar las páginas de su elección a través de vectores no especificados. • http://drupal.org/node/1417186 http://drupal.org/node/1461438 http://secunia.com/advisories/48196 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/79772 http://www.securityfocus.com/bid/52232 https://exchange.xforce.ibmcloud.com/vulnerabilities/73608 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-2069
https://notcve.org/view.php?id=CVE-2012-2069
Cross-site request forgery (CSRF) vulnerability in the Wishlist module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.6 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences via the (1) wl_reveal or (2) q parameters. Vulnerabilidad de fasificación de peticiones en sitios cruzados (CSRF) en el módulo Wishlist v6.x-2.x anterior a v6.x-2.6 y 7.x-2.x anterior a v7.x-2.6 para Drupal permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios para las solicitudes que insertan cross-site scripting (XSS) secuencias a través de la wl_reveal (1) o (2) los parámetros q. • http://drupal.org/node/1483634 http://drupal.org/node/1483636 http://drupal.org/node/1492624 http://drupalcode.org/project/wishlist.git/commit/6660c33 http://drupalcode.org/project/wishlist.git/commit/73aaf98 http://secunia.com/advisories/48486 http://www.madirish.net/content/drupal-wishlist-6x-24-xss-vulnerability http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52660 • CWE-352: Cross-Site Request Forgery (CSRF) •