
CVE-2013-0257
https://notcve.org/view.php?id=CVE-2013-0257
27 Mar 2013 — The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields. El módulo email2image v6.x-1.x y v6.x-2.x para Drupal no restringe debidamente el acceso a los nodos, lo que permite a atacantes remotos leer las imágenes de las direcciones de correo electrónico del usuario y los campos de correo electrónico. • http://drupal.org/node/1903264 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-0319
https://notcve.org/view.php?id=CVE-2013-0319
27 Mar 2013 — Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data. Vulnerabilidad de XSS en el módulo Yandex.Metrics 6.x-1.x anterior a 6.x-1.6 y 7.x-1.x anterior a 7.x-1.5 para Drupal, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores que involucran al servicio de datos Yandex.Metrica. • http://drupal.org/node/1921340 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-0320
https://notcve.org/view.php?id=CVE-2013-0320
27 Mar 2013 — Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en el Administrador de Taxonomía (taxonomy_manager) módulo v6.x-2.x antes v6.x-2.2 y v7.x-1.x antes v7.x-1.0-rc1 para Drupal permite a atacantes remotos ... • http://drupal.org/node/1922168 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2013-0321
https://notcve.org/view.php?id=CVE-2013-0321
27 Mar 2013 — Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field. Vulnerabilidad de e jecución de secuencias de comandos en sitios cruzados(XSS) en Views en el modulo Ubercart Views (uc_views) v6.x módulo antes de v6.x-3.3 para Drupal que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del campo Nombre completo. • http://drupal.org/node/1922128 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-0325
https://notcve.org/view.php?id=CVE-2013-0325
27 Mar 2013 — Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting. Multiples cross-site scripting (XSS) en el modulo Varnish v6.x-1.x anterior a v6.x-1.2 y v7.x-1.x anterior a v7.x-1.0-beta2 para Drupal permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) mensajes Watchdog o (2) conf... • http://drupal.org/node/1922726 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-0206
https://notcve.org/view.php?id=CVE-2013-0206
19 Mar 2013 — Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. Vulnerabilidad de subida de archivos sin restricciones en el módulo CSS en vivo v6.x-2.x antes v6.x-2.1 y v7.x-2.x antes v7.x-2.7 para Drupal que permite a usuar... • http://drupal.org/node/1883976 •

CVE-2013-0225
https://notcve.org/view.php?id=CVE-2013-0225
19 Mar 2013 — Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo User Relationships v6.x-1.x anterior a v6.x-1.4 y v7.x-1.x anterior a v7.x-1.0-alpha5 para Drupal, permite a usuarios remotos au... • http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-5651 – Debian Security Advisory 2776-1
https://notcve.org/view.php?id=CVE-2012-5651
03 Jan 2013 — Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results. Drupal v6.x antes de v6.27 y v7.x antes de v7.18 muestra información a los usuarios bloqueados, lo que podría permitir a atacantes remotos obtener información sensible mediante la lectura de los resultados de búsqueda. Multiple vulnerabilities have been been fixed in the Drupal content management framework, resulting in informati... • http://drupal.org/SA-CORE-2012-004 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2012-5652 – Debian Security Advisory 2776-1
https://notcve.org/view.php?id=CVE-2012-5652
03 Jan 2013 — Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. Drupal v6.x antes de v6.27 permite a atacantes remotos obtener información sensible acerca de los archivos subidos a través de un (1) feed RSS o (2) resultados de búsqueda. Multiple vulnerabilities have been been fixed in the Drupal content management framework, resulting in information disclosure, insufficient validation, cross-site scripting and cross-site request fo... • http://drupal.org/SA-CORE-2012-004 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2012-5653 – Debian Security Advisory 2776-1
https://notcve.org/view.php?id=CVE-2012-5653
03 Jan 2013 — The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name. La característica de carga de archivos en Drupal v6.x antes de v6.27 y v7.x antes de v7.18 permite a usuarios remotos autenticados eludir el mecanismo de protección y ejecutar código PHP arbitrario a través de un byte nulo en un nombre de archivo. Multiple vulnerabilities have been been fixed in the Drupal co... • http://drupal.org/SA-CORE-2012-004 • CWE-20: Improper Input Validation •