CVE-2012-4554 – Drupal OpenID External Entity Injection
https://notcve.org/view.php?id=CVE-2012-4554
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file. El módulo OpenID en Drupal v7.x antes de v7.16 permite a servidores OpenID remotos leer archivos arbitrarios mediante una declaración DOCTYPE manipulada en un archivo XRDS. • http://drupal.org/node/1815912 http://drupalcode.org/project/drupal.git/commit/b912710 http://www.openwall.com/lists/oss-security/2012/10/29/4 http://www.openwall.com/lists/oss-security/2012/10/30/5 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-4553
https://notcve.org/view.php?id=CVE-2012-4553
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions." Drupal v7.x antes de v7.16 permite a atacantes remotos obtener información sensible y posiblemente reinstalar Drupal y ejecutar código PHP arbitrario a través de un servidor de base de datos externa, relacionado con "las condiciones transitorias". • http://drupal.org/node/1815904 http://drupal.org/node/1815912 http://drupalcode.org/project/drupal.git/commit/b912710 http://www.openwall.com/lists/oss-security/2012/10/29/4 http://www.openwall.com/lists/oss-security/2012/10/30/5 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-4486
https://notcve.org/view.php?id=CVE-2012-4486
Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that switch the user to a subuser via unspecified vectors. Una vulnerabilidad de Falsificación de petición en sitios cruzados (CSRF) en el módulo Subuser antes de v6.x-1.8 para Drupal permite a atacantes remotos secuestrar la autenticación de usuarios de su elección para las solicitudes que se cambian el rol de un usuario al de un subusuario a través de vectores no especificados. • http://drupal.org/node/1700550 http://drupal.org/node/1700584 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2012-4498
https://notcve.org/view.php?id=CVE-2012-4498
The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restrictions and possibly have other unspecified impact. El módulo Activism v6.x-2.x antes de v6.x-2.1 para Drupal no restringe adecuadamente el acceso al tipo de contenido "Campaña", lo que podría permitir a atacantes remotos evitar las restricciones de acceso y posiblemente tener un impacto no especificado. • http://drupal.org/node/1762152 http://drupal.org/node/1762160 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-4487
https://notcve.org/view.php?id=CVE-2012-4487
The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created. El módulo Subuser antes de v6.x-1.8 para Drupal no comprueba correctamente los permisos "switch subuser", lo que permite cambiar su rol a usuarios remotos autenticados por el de un subusuario que éste haya creado. • http://drupal.org/node/1700550 http://drupal.org/node/1700584 http://www.openwall.com/lists/oss-security/2012/10/04/6 http://www.openwall.com/lists/oss-security/2012/10/07/1 • CWE-264: Permissions, Privileges, and Access Controls •