CVE-2012-6582
https://notcve.org/view.php?id=CVE-2012-6582
Cross-site scripting (XSS) vulnerability in the Spambot module 6.x-3.x before 6.x-3.2 and 7.x-1.x before 7.x-1.1 for Drupal allows certain remote attackers to inject arbitrary web script or HTML via a stopforumspam.com API response, which is logged by the watchdog. Vulnerabilidad XSS en el módulo Spambot 6.x-3.x anterior a 6.x-3.2 y 7.x-1.x anterior a 7.x-1.1 para Drupal, permite a determinados atacantes inyectar secuencias de comandos web o HTML arbitrarias a través de respuestas de la API stopforumspam.com cuando se ha logado por el "watchdog". • http://osvdb.org/85680 http://secunia.com/advisories/50670 http://www.securityfocus.com/bid/55613 https://drupal.org/node/1789084 https://drupal.org/node/1789086 https://drupal.org/node/1789242 https://exchange.xforce.ibmcloud.com/vulnerabilities/78701 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-5315
https://notcve.org/view.php?id=CVE-2013-5315
Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than CVE-2013-4174. Vulnerabilidad XSS en el submódulo Resource Manager en el submódulo MEE (mee.module) en el módulo Scald 6.x-1.x anterior a 6.x-1.0-beta3 y 7.x-1.x anterior a 7.x-1.1 para Drupal, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrario a través de un título atom. Vulnerabilidad distinta de CVE-2013-4174. • http://drupalcode.org/project/scald.git/blobdiff/9ce68f67a25200afa5256f567ef89bc4b9fd705e..974a5e29f502a58e6a955d69a85bb5f16c1c8b3e:/mee/mee.module http://drupalcode.org/project/scald.git/commitdiff/32db1ee http://osvdb.org/95625 http://seclists.org/fulldisclosure/2013/Jul/224 http://secunia.com/advisories/54144 http://www.securityfocus.com/bid/61426 https://drupal.org/node/2049239 https://drupal.org/node/2049415 https://exchange.xforce.ibmcloud.com/vulnerabilities/85964 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-4174
https://notcve.org/view.php?id=CVE-2013-4174
Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flash_width, or (3) flash_height in the scald_flash_scald_prerender function in providers/scald_flash/scald_flash.module; or the (4) caption in the scald_image_scald_prerender function in providers/scald_image/scald_image.module. Múltiples vulnerabilidades XSS en el módulo Scald 7.x-1.x anterior a 7.x-1.1 para Drupal, permite a tacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de (1) flash_uri, (2) flash_width, o (3) flash_height en la función scald_flash_scald_prerender en providers/scald_flash/scald_flash.module; o el (4) caption en la función scald_image_scald_prerender en providers/scald_image/scald_image.module. • http://drupalcode.org/project/scald.git/commitdiff/32db1ee http://osvdb.org/95625 http://seclists.org/fulldisclosure/2013/Jul/224 http://secunia.com/advisories/54144 http://www.securityfocus.com/bid/61426 https://drupal.org/node/2049251 https://drupal.org/node/2049415 https://exchange.xforce.ibmcloud.com/vulnerabilities/85964 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-4140
https://notcve.org/view.php?id=CVE-2013-4140
Cross-site scripting (XSS) vulnerability in the TinyBox (Simple Splash) module before 7.x-2.2 for Drupal allows remote authenticated users with the "administer tinybox" permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en el módulo TinyBox (Simple Splash) 7.x-2.2 para Drupal, permite a usuarios autenticados remotamente con permisos de "administración de tynibox", inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://osvdb.org/95153 http://seclists.org/fulldisclosure/2013/Jul/86 http://secunia.com/advisories/54091 http://www.openwall.com/lists/oss-security/2013/07/17/1 http://www.securityfocus.com/bid/61078 https://drupal.org/node/2031575 https://drupal.org/node/2038807 https://exchange.xforce.ibmcloud.com/vulnerabilities/85600 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0246
https://notcve.org/view.php?id=CVE-2013-0246
The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors. El módulo Image en Drupal v7.x anterior a v7.19, cuando un sistema de ficheros privado es utilizado, no restringe adecuadamente el acceso a imágenes derivadas, lo que permite a atacantes remotos leer imágenes derivadas de imágenes restringidas a través de vectores no especificados. • http://packetstormsecurity.com/files/119598/Drupal-Core-6.x-7.x-Cross-Site-Scripting-Access-Bypass.html http://seclists.org/fulldisclosure/2013/Jan/120 http://seclists.org/oss-sec/2013/q1/211 http://secunia.com/advisories/51717 https://drupal.org/SA-CORE-2013-001 • CWE-264: Permissions, Privileges, and Access Controls •