CVE-2013-1779
https://notcve.org/view.php?id=CVE-2013-1779
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la "galería de 3 diapositivas" en el tema Fresh anterior a v7.x-1.4 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1723316 http://drupal.org/node/1929482 http://drupalcode.org/project/fresh.git/commitdiff/08a3ccb http://www.openwall.com/lists/oss-security/2013/02/28/3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1780
https://notcve.org/view.php?id=CVE-2013-1780
Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el tema Best Responsive v7.x-1.x anterior a v7.x-1.4 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores relacionados con los iconos sociales. • http://drupal.org/node/1929390 http://drupal.org/node/1929484 http://drupalcode.org/project/best_responsive.git/commitdiff/5972126 http://osvdb.org/90690 http://secunia.com/advisories/52421 http://www.openwall.com/lists/oss-security/2013/02/28/3 http://www.securityfocus.com/bid/58213 https://exchange.xforce.ibmcloud.com/vulnerabilities/82469 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1781
https://notcve.org/view.php?id=CVE-2013-1781
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la "galería de 3 diapositivas" en el tema Professional anterior a v7.x-1.4 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1730768 http://drupal.org/node/1929486 http://drupalcode.org/project/professional_theme.git/commitdiff/0640ddc http://drupalcode.org/project/professional_theme.git/commitdiff/e3fa6a2 http://www.openwall.com/lists/oss-security/2013/02/28/3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1786
https://notcve.org/view.php?id=CVE-2013-1786
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la "galería de 3 diapositivas" del tema Company anterior a v7.x-1.4 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1724232 http://drupal.org/node/1929512 http://drupalcode.org/project/company.git/commitdiff/9ddac7e http://drupalcode.org/project/company.git/commitdiff/d9a99da http://www.openwall.com/lists/oss-security/2013/02/28/3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1859
https://notcve.org/view.php?id=CVE-2013-1859
The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors. El modulo Node Parameter Control v6.x-1.x para Drupal no restringe correctamente el acceso a las opciones de configuración, que permite a atacantes remotos leer y editar las opciones de configuración a través de vectores no especificados. • http://drupal.org/node/1942330 http://osvdb.org/91257 http://packetstormsecurity.com/files/120788/Drupal-Node-Parameter-Control-6.x-Access-Bypass.html http://seclists.org/fulldisclosure/2013/Mar/133 http://www.openwall.com/lists/oss-security/2013/03/15/2 • CWE-264: Permissions, Privileges, and Access Controls •