![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6659 – Debian Security Advisory 3346-1
https://notcve.org/view.php?id=CVE-2015-6659
24 Aug 2015 — SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment. Vulnerabilidad de inyección SQL en el sistema de filtrado de comentarios en la API Database en Drupal 7.x en versiones anteriores a 7.39, permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de un comentario SQL. Several vulnerabilities were discovered in Drupal, a content management framework. • http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6660 – Debian Security Advisory 3346-1
https://notcve.org/view.php?id=CVE-2015-6660
24 Aug 2015 — The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks." Vulnerabilidad en la API Form en Drupal 6.x en versiones anteriores a 6.37 y 7.x en versiones anteriores a 7.39, no valida correctamente el token form, lo cual permite a atacantes remotos realizar ataques CSRF que cargan archivos en diferentes cuentas de... • http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html • CWE-352: Cross-Site Request Forgery (CSRF) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6661 – Debian Security Advisory 3346-1
https://notcve.org/view.php?id=CVE-2015-6661
24 Aug 2015 — Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu. Vulnerabilidad en Drupal 6.x en versiones anteriores a 6.37 y 7.x en versiones anteriores a 7.39, permite a atacantes remotos obtener títulos sensibles de nodo leyendo el menú. Several vulnerabilities were discovered in Drupal, a content management framework. • http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-6665 – Debian Security Advisory 3346-1
https://notcve.org/view.php?id=CVE-2015-6665
24 Aug 2015 — Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag. Vulnerabilidad de XSS en el manejador Ajax en Drupal 7.x en versiones anteriores a la 7.39 y el módulo Ctools 6.x-1.x en versiones anteriores a 6.x-1.14 para Drupal, permite a atacantes remotos inyectar secuencias de coman... • http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-3234 – Debian Security Advisory 3291-1
https://notcve.org/view.php?id=CVE-2015-3234
18 Jun 2015 — The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers. El módulo OpenID en Drupal 6.x anterior a 6.36 y 7.x anterior a 7.38 permite a atacantes remotos iniciar sesión en las cuentas de otros usuarios mediante el aprovechamiento de una identidad OpenID de ciertos proveedores, tal y como fue demostrado por los pro... • http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-3231 – Debian Security Advisory 3291-1
https://notcve.org/view.php?id=CVE-2015-3231
18 Jun 2015 — The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache. El sistema de caché Render en Drupal 7.x anterior a 7.38, cuando se utiliza para cachear contenido por roles de usuario, permite a usuarios remotos autenticados obtener contenido privado visualizado por el usuario 1 mediante la lectura del caché. Several vulnerabilities were found in drupal7, a content management platfo... • http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-3232 – Debian Security Advisory 3291-1
https://notcve.org/view.php?id=CVE-2015-3232
18 Jun 2015 — Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter. Vulnerabilidad de la redirección abierta en el módulo Field UI en Drupal 7.x anterior a 7.38 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través de una URL en el parámetro destinations. Several vulnerabilities were found in drupal7, a c... • http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-3233 – Debian Security Advisory 3291-1
https://notcve.org/view.php?id=CVE-2015-3233
18 Jun 2015 — Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de la redirección abierta en el módulo Overlay en Drupal 7.x anterior a 7.38 permite a atacantes remotos autenticados redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través de vectores no especificados. Several vulnerabilities were found in drupal7, a content managemen... • http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161261.html •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-2750 – Mandriva Linux Security Advisory 2015-181
https://notcve.org/view.php?id=CVE-2015-2750
31 Mar 2015 — Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence. Una vulnerabilidad de redirección abierta en funciones de API relacionadas con URL en Drupal, en las versiones 6.x anteriores a la 6.35 y 7.x anteriores a la 7.35 permite a atacantes remotos redirigir a los usuarios a páginas web arbitrarias y realizar ataques de ph... • http://cgit.drupalcode.org/drupal/commit/includes/common.inc?h=7.x&id=b44056d2f8e8c71d35c85ec5c2fb8f7c8a02d8a8 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2015-2749 – Mandriva Linux Security Advisory 2015-181
https://notcve.org/view.php?id=CVE-2015-2749
31 Mar 2015 — Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. Una vulnerabilidad de redirección abierta en Drupal en las versiones 6.x anteriores a la 6.35 y 7.x anteriores a la 7.35 permite a atacantes remotos redirigir a los usuarios a páginas web arbitrarias y realizar ataques de phishing mediante una URL en el parámetro destination. Updated drupal packages fix... • http://cgit.drupalcode.org/drupal/commit/?id=d2304f840c43c190c6e136ee9901ed9797b4c3ca • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •