2 results (0.008 seconds)

CVSS: 7.5EPSS: 0%CPEs: 18EXPL: 0

Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, does not properly restrict access when displaying node titles, which has unknown impact and attack vectors. Nodequeue v5.x anteriores a v5.x-2.7 y v6.x anteriores a v6.x-2.2, un modulo para Drupal, nos restringe adecuadamente cuando se visualizan los títulos de nodo, lo que tiene un impacto y vectores desconocidos. • http://drupal.org/node/488092 http://drupal.org/node/488102 http://drupal.org/node/488104 http://secunia.com/advisories/35424 http://www.securityfocus.com/bid/35305 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 3.5EPSS: 0%CPEs: 14EXPL: 1

Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via vocabulary names. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Nodequeue v5.x anteriores a v5.x-2.7 y v6.x anteriores a v6.x-2.2, un modulo para Drupal, permite a usuarios remotos autenticados con permisos administrativos taxonómicos inyectar secuencias de comandos web o HTML de forma arbitraria a través de nombres de vocabulario. • http://drupal.org/node/488092 http://drupal.org/node/488102 http://drupal.org/node/488104 http://lampsecurity.org/drupal-nodeque-xss-vulnerability http://secunia.com/advisories/35424 http://www.securityfocus.com/bid/35305 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •