CVE-2012-2081
https://notcve.org/view.php?id=CVE-2012-2081
The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive information such as private group titles via a request through the Views module. El módulo 'Organic Groups' (OG) v6.x-2.x, antes de v6.x-2.3 para Drupal no restringe adecuadamente el acceso, lo que permite a atacantes remotos obtener información sensible, tales como títulos de los grupos privados a través de una solicitud a través del módulo de Vistas (Views). • http://drupal.org/node/1507328 http://drupal.org/node/1507446 http://osvdb.org/80678 http://secunia.com/advisories/48620 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52799 https://exchange.xforce.ibmcloud.com/vulnerabilities/74526 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-2074
https://notcve.org/view.php?id=CVE-2012-2074
Unspecified vulnerability in certain default views in the Ubercart Views module 6.x before 6.x-3.2 for Drupal allows remote attackers to obtain sensitive information via unknown attack vectors. Una vulnerabilidad no especificada en ciertas vistas por defecto en el módulo Ubercart Views v6.x antes de v6.x-3.2 para Drupal permite a atacantes remotos obtener información sensible a través de vectores de ataque desconocidos. • http://drupal.org/node/1505210 http://drupal.org/node/1506428 http://osvdb.org/80677 http://secunia.com/advisories/48631 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52814 https://exchange.xforce.ibmcloud.com/vulnerabilities/74485 •
CVE-2012-2075
https://notcve.org/view.php?id=CVE-2012-2075
Cross-site scripting (XSS) vulnerability in the Contact Save module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the access site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el módulo "Contact Save" v6.x-1.x antes de v6.x-1.5 para Drupal permite inyectar secuencias de comandos web o HTML, a usuarios remotos autenticados con permisos de acceso a todos los formularios del sitio web, a través de vectores no especificados. • http://drupal.org/node/1506438 http://drupal.org/node/953788 http://drupalcode.org/project/contact_save.git/commit/0654894 http://osvdb.org/80669 http://secunia.com/advisories/48619 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52787 https://exchange.xforce.ibmcloud.com/vulnerabilities/74515 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2154
https://notcve.org/view.php?id=CVE-2012-2154
Cross-site scripting (XSS) vulnerability in the CDN2 Video module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el Módulo de vídeo CDN2 v6.x para Drupal permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://drupal.org/node/1506542 http://osvdb.org/80685 http://www.openwall.com/lists/oss-security/2012/05/03/1 http://www.openwall.com/lists/oss-security/2012/05/03/2 http://www.securityfocus.com/bid/52812 https://exchange.xforce.ibmcloud.com/vulnerabilities/74520 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-2071
https://notcve.org/view.php?id=CVE-2012-2071
Cross-site scripting (XSS) vulnerability in the Contact Forms module 6.x-1.x before 6.x-1.13 for Drupal when the core contact form is enabled, allows remote authenticated users with the administer site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el módulo "Contact Forms" v6.x-1.x antes de v6.x-1.13 para Drupal, cuando el formulario de contacto central está activado, permite inyectar secuencias de comandos web o HTML, a usuarios remotos autenticados con permisos de administración de formularios de contacto en todo el sitio web, a través de vectores no especificados. • http://drupal.org/node/1506330 http://drupal.org/node/1506404 http://osvdb.org/80674 http://secunia.com/advisories/48583 http://www.openwall.com/lists/oss-security/2012/04/07/1 http://www.securityfocus.com/bid/52801 https://exchange.xforce.ibmcloud.com/vulnerabilities/74467 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •