CVE-2013-1971
https://notcve.org/view.php?id=CVE-2013-1971
Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file. Múltiples vulnerabilidades de cross-site scripting (XSS) en el módulo MP3 Player para Drupal v6.x que permite a usuarios autenticados remotamente inyectar código script o HTML a través del nombre del fichero MP3. • http://www.securityfocus.com/bid/59276 https://drupal.org/node/1972804 https://exchange.xforce.ibmcloud.com/vulnerabilities/83649 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-2036
https://notcve.org/view.php?id=CVE-2013-2036
Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files." Vulnerabilidad XSS en el módulo Filebrowser 6.x-2.x anterior 6.x-1.1 para Drupal permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de vectores no especificados relacionados con una lista de archivos. • http://secunia.com/advisories/53228 https://drupal.org/node/1983356 https://drupal.org/node/1984212 https://exchange.xforce.ibmcloud.com/vulnerabilities/83986 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1972
https://notcve.org/view.php?id=CVE-2013-1972
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors. Vulnerabilidad CSRF en el módulo para la gestión de archivos elFinder 6.x-0.x anterior a 6.x-0.8 y 7.x-0.x anterior a 7.x-0.8 para Drupal, permite a atacantes remotos secuestrar la auntenticación de víctimas no especificadas para crear, modificar o eliminar archivos a través de vectores desconocidos. • http://archives.neohapsis.com/archives/fulldisclosure/2013-04/0237.html http://osvdb.org/92533 https://drupal.org/node/1972082 https://drupal.org/node/1972084 https://drupal.org/node/1972942 https://exchange.xforce.ibmcloud.com/vulnerabilities/83651 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1906
https://notcve.org/view.php?id=CVE-2013-1906
Cross-site scripting (XSS) vulnerability in the Rules module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "administer rules" permission to inject arbitrary web script or HTML via a rule tag. Vulnerabilidad XSS en el módulo Rules 7.x-2.x anterior a 7.x-2.3 para Drupal, permite a usuarios autenticados remotamente con los permisos "administrator rules" inyectar secuencias de comandos web o HTML de su elección a través de una etiqueta "rule". • http://secunia.com/advisories/52768 https://drupal.org/node/1954508 https://drupal.org/node/1954592 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-2129
https://notcve.org/view.php?id=CVE-2013-2129
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all webform content" permissions to inject arbitrary web script or HTML via a component label. Vulnerabilidad XSS en el módulo WebForm 6.x-3.x anterior 6.x-3.19 para Drupal permite a usuarios autenticados con los permisos para edit own webform content" o "edit all webform content" inyectar secuencias de comandos web o HTML arbitrarias a través de una etiqueta del componente. • http://osvdb.org/93749 http://secunia.com/advisories/53184 http://www.securityfocus.com/bid/60218 https://drupal.org/node/2007390 https://drupal.org/node/2007460 https://exchange.xforce.ibmcloud.com/vulnerabilities/84628 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •