CVE-2013-4384
https://notcve.org/view.php?id=CVE-2013-4384
Cross-site scripting (XSS) vulnerability in Google Site Search module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10 for Drupal allows remote attackers to inject arbitrary web script or HTML by causing crafted data to be returned by the Google API. Vulnerabilidad de XSS en el módulo Google Site Search 6.x-1.x anterior a la versión 6.x-1.4 y 7.x-1.x anterior a 7.x-1.10 para Drupal permite a atacantes remotos inyectar script web arbitrario o HTML, provocando que datos diseñados sean devueltos por la API de Google. • http://osvdb.org/97503 http://www.securityfocus.com/bid/62495 https://drupal.org/node/2092395 https://exchange.xforce.ibmcloud.com/vulnerabilities/87285 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-5965
https://notcve.org/view.php?id=CVE-2013-5965
The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing. El módulo Node View permissions 7.x-1-x (anteriores a 7.x-1.2) para Drupal no implementa apropiadamente la función hook_query_alter, lo que podría permitir a atacantes remotos obtener información sensible leyendo la lista de nodos. • http://archives.neohapsis.com/archives/bugtraq/2013-08/0184.html http://secunia.com/advisories/54550 http://www.openwall.com/lists/oss-security/2013/09/11/9 https://drupal.org/node/2031621 https://drupal.org/node/2076315 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2013-5964
https://notcve.org/view.php?id=CVE-2013-5964
Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title. Vulnerabilidad cross-site scripting (XSS) en la página de administración del módulo Flag 7.x-3.x anteriores a 7.x-3.1 para Drupal permite a usuarios autenticados remotos con permisos "Administer flags" inyectar script web o HTML a través del título de flag. • http://archives.neohapsis.com/archives/bugtraq/2013-08/0184.html http://osvdb.org/96750 http://seclists.org/fulldisclosure/2013/Aug/287 https://drupal.org/node/2075287 https://drupal.org/node/2076221 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-5938
https://notcve.org/view.php?id=CVE-2013-5938
Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form. Vulnerabilidad XSS en el módulo Click2Sell Suite v6.x-1.x para Drupal permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de un formulario de confirmación. • http://osvdb.org/97204 http://seclists.org/fulldisclosure/2013/Sep/64 http://www.openwall.com/lists/oss-security/2013/10/21/5 https://drupal.org/node/2087055 https://exchange.xforce.ibmcloud.com/vulnerabilities/87050 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-5937
https://notcve.org/view.php?id=CVE-2013-5937
Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API. Vulnerabilidad CSRF en el módulo Click2Sell Suite v6.x-1.x para Drupal permite a atacantes remotos secuestrar la autenticación de administradores para peticiones que eliminen información de la base de datos a través de vectores que involucran la API Drupal Form. • http://osvdb.org/97203 http://seclists.org/fulldisclosure/2013/Sep/64 http://www.openwall.com/lists/oss-security/2013/10/21/5 https://drupal.org/node/2087055 https://exchange.xforce.ibmcloud.com/vulnerabilities/87052 • CWE-352: Cross-Site Request Forgery (CSRF) •