
CVE-2007-5621
https://notcve.org/view.php?id=CVE-2007-5621
22 Oct 2007 — Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames. Múltiples vulnerabilidades de secuencias de ... • http://drupal.org/node/184336 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2006-4646
https://notcve.org/view.php?id=CVE-2006-4646
08 Sep 2006 — Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Pathauto module before pathauto_node.inc 1.17.2.1 and the Drupal 4.6 Pathauto module before pathauto_node.inc 1.14.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados en el módulo Drupal 4.7 Pathauto anterior a pathauto_node.inc 1.17.2.1 y el módulo Drupal 4.6 Pathauto anterior a pathauto_node.inc 1.14.2.1, permite a un atacante remoto inyectar secuen... • http://drupal.org/node/82527 •