CVE-2012-2065
https://notcve.org/view.php?id=CVE-2012-2065
Cross-site scripting (XSS) vulnerability in the Language Icons module 6.x-2.x before 6.x-2.1 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with administer languages permissions to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de código en sitios cruzados (XSS) en el módulo Language Icons v6.x-2.x anterior a v6.x-2.1 y v7.x-1.x anterior a v7.x-1.0 para Drupal permite a usuarios remotos autenticados administrar permisos de idiomas para inyectar secuencias de comandos web o HTML a través de vectores no especificados • http://drupal.org/node/1482136 http://drupal.org/node/1482144 http://drupal.org/node/1482428 http://drupalcode.org/project/languageicons.git/commit/be620bb http://drupalcode.org/project/languageicons.git/commit/e3f3f1f http://secunia.com/advisories/48405 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/80070 http://www.securityfocus.com/bid/52499 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2066
https://notcve.org/view.php?id=CVE-2012-2066
Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated users or remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de código en sitios cruzados (XSS) en el módulo FCKeditor v6.x-2.x anterior a v6.x-2.3 y el módulo CKEditor v6.x-1.x anterior a v6.x-1.9 y v77.x-1.x anterior a v7.x-1.7 para Drupal permite a usuarios remotos autenticados o atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1482442 http://drupal.org/node/1482466 http://drupal.org/node/1482480 http://drupal.org/node/1482528 http://secunia.com/advisories/48435 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/80079 https://exchange.xforce.ibmcloud.com/vulnerabilities/74036 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2116
https://notcve.org/view.php?id=CVE-2012-2116
Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart. Vulnerabilidad de fasificación de peticiones en sitios cruzados (CSRF) en el módulo Commerce Reorder anteriores a v7.x-1.1 para Drupal permite a atacantes remotos secuestrar la autenticación de los usuarios en peticiones que añaden artículos al carro de la compra. • http://drupal.org/node/1538198 http://drupalcode.org/project/commerce_reorder.git/commit/bf060ab http://secunia.com/advisories/48912 http://www.openwall.com/lists/oss-security/2012/04/18/11 http://www.openwall.com/lists/oss-security/2012/04/19/1 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2012-1641
https://notcve.org/view.php?id=CVE-2012-1641
The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenticated users with the administer finder permission to execute arbitrary PHP code via admin/build/finder/import. La función finder_import en el módulo Finder v6.x-1.x anterior a v6.x-1.26, v7.x-1.x, y v7.x-2.x anterior a v7.x-2.0-alpha8 para Drupal permite a usuarios remotos autenticados con permisos de administración del finder ejecutar código PHP arbitrario a través de admin/build/finder/import. • http://drupal.org/node/1432318 http://drupal.org/node/1432320 http://drupalcode.org/project/finder.git/commit/bc0cc82 http://secunia.com/advisories/47915 http://secunia.com/advisories/47943 http://www.madirish.net/content/drupal-finder-6x-19-xss-and-remote-code-execution-vulnerabilities http://www.openwall.com/lists/oss-security/2012/03/16/9 http://www.openwall.com/lists/oss-security/2012/03/19/9 http://www.openwall.com/lists/oss-security/2012/04/07/1 http:/ • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-1643
https://notcve.org/view.php?id=CVE-2012-1643
The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers to modify access permissions via unspecified vectors. El módulo Faster Persmissions v7.x-2.x anterior a v7.x-1.2 para Drupal no comprueba los permisos "administer permissions", lo cual permite a atacantes remotos modificar los permisos de acceso a través de vectores desconocidos. • http://drupal.org/node/1441556 http://drupalcode.org/project/fp.git/commitdiff/39e7587 http://secunia.com/advisories/48019 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.osvdb.org/79316 https://drupal.org/node/1441448 • CWE-264: Permissions, Privileges, and Access Controls •