CVE-2013-1783
https://notcve.org/view.php?id=CVE-2013-1783
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la "galería de 3 diapositivas" en la pagina front.tpl.php del tema Business anterior a v7.x-1.8 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1723246 http://drupal.org/node/1929496 http://drupalcode.org/project/business.git/commitdiff/02f081f http://osvdb.org/90685 http://secunia.com/advisories/52424 http://www.openwall.com/lists/oss-security/2013/02/28/3 http://www.securityfocus.com/bid/58216 https://exchange.xforce.ibmcloud.com/vulnerabilities/82460 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-1785
https://notcve.org/view.php?id=CVE-2013-1785
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Premium Responsive theme before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la "galería de 3 diapositivas" del tema Premium Responsive anterior a v7.x-1.4 para Drupal permite a usuarios remotos autenticados con permisos para administrar temas inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1730752 http://drupal.org/node/1929508 http://drupalcode.org/project/responsive.git/commitdiff/1c6fa91 http://drupalcode.org/project/responsive.git/commitdiff/6b593ff http://www.openwall.com/lists/oss-security/2013/02/28/3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0320
https://notcve.org/view.php?id=CVE-2013-0320
Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el Administrador de Taxonomía (taxonomy_manager) módulo v6.x-2.x antes v6.x-2.2 y v7.x-1.x antes v7.x-1.0-rc1 para Drupal permite a atacantes remotos secuestrar a la autenticación de usuarios con el permiso 'administer taxonomy' a ??través de vectores no especificados. • http://drupal.org/node/1922168 http://drupal.org/node/1922170 http://drupal.org/node/1922410 http://drupalcode.org/project/taxonomy_manager.git/commitdiff/2d05801 http://drupalcode.org/project/taxonomy_manager.git/commitdiff/595f1b3 http://www.openwall.com/lists/oss-security/2013/02/21/5 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-0325
https://notcve.org/view.php?id=CVE-2013-0325
Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting. Multiples cross-site scripting (XSS) en el modulo Varnish v6.x-1.x anterior a v6.x-1.2 y v7.x-1.x anterior a v7.x-1.0-beta2 para Drupal permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) mensajes Watchdog o (2) configuración del administrador. • http://drupal.org/node/1922726 http://drupal.org/node/1922730 http://drupal.org/node/1922756 http://drupalcode.org/project/varnish.git/commitdiff/e6726b4 http://drupalcode.org/project/varnish.git/commitdiff/f69a62c http://www.openwall.com/lists/oss-security/2013/02/21/5 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-0259
https://notcve.org/view.php?id=CVE-2013-0259
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter. Ejecución de comandos en sitios cruzados (XSS) en el módulo Boxes v7.x-1.x antes v7.x-1.1 para Drupal que permite a usuarios remotos autenticados, con permiso para administrar o editar los permisos de las cajas, inyectar secuencias de comandos web o HTML a través del parámetro sujeto. • http://drupal.org/node/1897016 http://drupal.org/node/1903300 http://drupalcode.org/project/boxes.git/commitdiff/456ff8e http://www.openwall.com/lists/oss-security/2013/02/05/1 http://www.securityfocus.com/bid/57642 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •