CVE-2013-1906
https://notcve.org/view.php?id=CVE-2013-1906
Cross-site scripting (XSS) vulnerability in the Rules module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "administer rules" permission to inject arbitrary web script or HTML via a rule tag. Vulnerabilidad XSS en el módulo Rules 7.x-2.x anterior a 7.x-2.3 para Drupal, permite a usuarios autenticados remotamente con los permisos "administrator rules" inyectar secuencias de comandos web o HTML de su elección a través de una etiqueta "rule". • http://secunia.com/advisories/52768 https://drupal.org/node/1954508 https://drupal.org/node/1954592 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-2129
https://notcve.org/view.php?id=CVE-2013-2129
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all webform content" permissions to inject arbitrary web script or HTML via a component label. Vulnerabilidad XSS en el módulo WebForm 6.x-3.x anterior 6.x-3.19 para Drupal permite a usuarios autenticados con los permisos para edit own webform content" o "edit all webform content" inyectar secuencias de comandos web o HTML arbitrarias a través de una etiqueta del componente. • http://osvdb.org/93749 http://secunia.com/advisories/53184 http://www.securityfocus.com/bid/60218 https://drupal.org/node/2007390 https://drupal.org/node/2007460 https://exchange.xforce.ibmcloud.com/vulnerabilities/84628 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-6572
https://notcve.org/view.php?id=CVE-2012-6572
Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary name. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en la función phptemplate_preprocess_node en template.php en el tema Inf08 v6.x-1.x anterior a v6.x-1.10 para Drupal, permite a atacantes remotos con el permiso "administer taxonomy" inyectar secuencias de comandos web o HTML. • http://osvdb.org/85422 http://secunia.com/advisories/50557 http://www.madirish.net/550 https://drupal.org/node/1782286 https://drupal.org/node/1782686 https://exchange.xforce.ibmcloud.com/vulnerabilities/78575 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1905
https://notcve.org/view.php?id=CVE-2013-1905
Cross-site scripting (XSS) vulnerability in the Zero Point theme 7.x-1.x before 7.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidades de secuencias de comandos entre sitios múltiples (XSS) en el tema Zero Point v7.x-1.x antes de 7.x-1.9 para Drupal que permite a atacantes remotos inyectar código web script o HTML a través de vectores sin especificar. • http://drupal.org/node/1954588 http://osvdb.org/91745 http://packetstormsecurity.com/files/120985/Drupal-Zero-Point-7.x-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2013/Mar/241 http://secunia.com/advisories/52775 http://www.securityfocus.com/bid/58758 https://drupal.org/node/1953840 https://exchange.xforce.ibmcloud.com/vulnerabilities/83137 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1887
https://notcve.org/view.php?id=CVE-2013-1887
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via certain view configuration fields. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en el modulo Views v7.x-3.x anterior a v7.x-3.6 para Drupal permite a usuarios autenticados remotamente con algunos permisos inyectar secuencias de comandos web o HTML a través de ciertos campos de la vista de configuración. • http://drupal.org/node/1948354 http://drupal.org/node/1948358 http://drupalcode.org/project/views.git/commitdiff/ddf8181bd13f69ffbeeee14ae72168418785d7ac http://packetstormsecurity.com/files/120892/Drupal-Views-7.x-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2013/Mar/193 http://secunia.com/advisories/51540 http://www.openwall.com/lists/oss-security/2013/03/22/8 http://www.openwall.com/lists/oss-security/2013/03/25/4 http://www.osvdb.org/91576 http://www.securit • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •