Page 6 of 52 results (0.358 seconds)

CVSS: 6.1EPSS: 0%CPEs: 44EXPL: 1

08 Jul 2009 — Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo Forum en Drupal v.6.x anteriores a v.6.13 permite a los atacantes remotos inyectar código web o HTM a través de vectores no especificados. • http://drupal.org/node/507572 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

08 Jul 2009 — Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. Drupal v.5.x anteriores a v.5.19 y 6.x anteriores a v.6.13 no limpian adecuadamente el intento de acceso fallido a páginas que contienen tablas ordenadas,que inclu... • http://drupal.org/node/507572 • CWE-255: Credentials Management Errors •