exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 100 RSS Feed

Files

Drupal Autosave 6.x / 7.x Cross Site Request Forgery
Posted Apr 12, 2012
Authored by Ryan Jud Hughes | Site drupal.org

The Drupal Autosave module versions 6.x and 7.x suffer from a cross site request forgery vulnerability.

tags | advisory, csrf
SHA-256 | a5010955517768867cfa38f156ec8127f1676c81935ed688afd452e6df38d04e

Related Files

Drupal Fancy Slide Cross Site Scripting
Posted Mar 15, 2012
Authored by Justin C. Klein Keane | Site drupal.org

The Fancy Slide module in Drupal 6.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | ce87c631b76cdb497819c7041674eeeb2c74a0e1c28234e06f9ed1159f8722b4
Drupal CKEditor / FCKeditor XSS / XSRF / Code Execution
Posted Mar 15, 2012
Authored by Heine Deelstra | Site drupal.org

CKEditor and FCKeditor modules in Drupal versions 6.x and 7.x suffer from PHP code execution, cross site request forgery, and cross site scripting vulnerabilities.

tags | advisory, php, vulnerability, code execution, xss, csrf
SHA-256 | aaa6ea9e677ff1cded922b9064a43bda0cfc2a65959bfa6b93813933823bdbd6
Drupal Language Icons Cross Site Scripting
Posted Mar 15, 2012
Authored by Frederik S. Olesen, Jose Reyero | Site drupal.org

The Language Icons module in Drupal versions 6.x and 7.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 23998b93437f4e5eff6ba6b5bbb1023e4ebe011636d6dfbb2128663087bcaf03
Drupal 7.x Views Language Switcher Cross Site Scripting
Posted Mar 15, 2012
Authored by Chris Ruppel | Site drupal.org

The Views Language Switcher in Drupal version 7.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | a2cff07f9cea7897070db7e929d453738c928b2a089313802fc27cd3235a7dc0
Drupal Slidebox 7.x Access Bypass
Posted Mar 14, 2012
Authored by Joshua Brauer | Site drupal.org

The Drupal Slidebox module version 7.x suffers from an access bypass vulnerability.

tags | advisory, bypass
SHA-256 | f39f6e32a9af3810fa3aeaaf69ffe9be44928d21b144ffbb5a12d5ab25364a21
Drupal Modules Cross Site Scripting / Cross Site Request Forgery
Posted Mar 14, 2012
Site drupal.org

Various Drupal modules such as Content Lock, Ubercart Bulk Stock Updater, Ubercart Payflow Link, ticketyboo News Ticker, Admin tools, and Redirecting click bouncer suffer from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities.

tags | advisory, remote, vulnerability, xss, sql injection, csrf
SHA-256 | dfba66004ce172b759e13bd0d69c968ca2876ae3c5a889fa13c062cb84aef994
Drupal Webform 6.x / 7.x Cross Site Scripting
Posted Mar 8, 2012
Authored by Kyle Small | Site drupal.org

The Drupal Webform module versions 6.x and 7.x suffer from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | ebc8afc7a8e3b9bc5101110a82c959641537ff9199390ac05b85f1fca3fab6b3
Drupal Node Recommendation 6.x Cross Site Scripting
Posted Mar 8, 2012
Authored by Dylan Tack | Site drupal.org

The Drupal Note Recommendation module version 6.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 0d5478a9de5ee767ee36f4e93e4cc328b19707ca13ca3a9371f41414d5cd9f89
Drupal Read More Link 6.x Cross Site Scripting
Posted Mar 8, 2012
Authored by Kyle Small | Site drupal.org

The Read More Link module version 6.x in Drupal allows you to move the "Read more" link from the node's links area to the end of the teaser text. A user could inject java script into pages affecting other site users. This vulnerability is mitigated by the fact that an attacker must have a role with the permission "access administration pages."

tags | advisory, java
SHA-256 | bd92348ee67235662934cb4a09b086c5d52b673a6df75c2193424fa80f15fba0
Drupal Block Class 7.x Cross Site Scripting
Posted Mar 7, 2012
Authored by Katherine Senzee | Site drupal.org

The Drupal block class module allows users to add classes to any block through the block's configuration interface The class names in a block were not properly filtered. Someone with the ability to modify or create blocks could inject java script that would be rendered when viewing the block. Blockclass versions prior to 7.x-1.0 are affected.

tags | advisory, java
SHA-256 | ec7bd4f2b0130760b1ad706dd01c6bc46328b023aed6daade7ba77de5c659f50
Drupal UC PayDutchGroup / WeDeal Payment / Multisite Search Disclosure
Posted Mar 7, 2012
Authored by Justin C. Klein Keane, Rolf Meijer | Site drupal.org

UC PayDutchGroup / WeDeal payment integrates the PayDutchGroup / WeDeal payment gateway with Ubercart. The module exposes account credentials for the store's PayDutchGroup account under certain circumstances allowing a malicious user to login to the PayDutchGroup site as the store owner and manage the store owner's account. The vulnerability is mitigated by an attacker needing to gain an account with the ability to checkout of the store. Multisite Search allows you to index and search content from all sites in a Multisite configuration. The module doesn't sufficiently escape user input when constructing queries. The vulnerability is mitigated by the fact that in order to execute arbitrary sql injection malicious users must have the ability to administer multisite search.

tags | advisory, arbitrary, sql injection
SHA-256 | 821d0c201eeac6fac0f5db639e8b855cdeb11ae6a13a35cc6a819fb54a37c7ce
Drupal Data 6.x-1.x Cross Site Scripting
Posted Mar 7, 2012
Authored by Justin C. Klein Keane | Site drupal.org

The Drupal Data module 6.x-1.x versions prior to 6.x-1.0 suffer from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 70f531879deaaf37ddbaa94bb6cc139601124e7c2ba8a519650348b97938972d
Taxonomy Views Integrator 6.x Cross Site Scripting
Posted Mar 1, 2012
Authored by Dmitry Trt | Site drupal.org

Taxonomy Views Integrator version 6.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 9d7a5cc3791c8cce6456f3e36c637e991adc01d9576564192e0f01a685d33576
Hierarchical Select 6.x Cross Site Scripting
Posted Mar 1, 2012
Authored by Sam Oldak, Wim Leers | Site drupal.org

Hierarchical Select version 6.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | dab2ead30f518286d0f151895e4d4d3de70b8b5d3652cdda89a58f8bc2395033
Submenu Tree 6.x Cross Site Scripting
Posted Mar 1, 2012
Authored by Kyle Small | Site drupal.org

Submenu Tree version 6.x suffers from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | 1ac8273c69c4b269cddb9fa7a80e500a8db89347597b52d760b92b4d9543bcd3
ZipCart 6.x Access Bypass
Posted Feb 29, 2012
Authored by Chris Burgess | Site drupal.org

ZipCart version 6.x suffers from an access bypass vulnerability.

tags | advisory, bypass
SHA-256 | 0e9f709682d4ce2cc90cfcee885a9245af53e3bf08a6c86a5d9e2949587d7bc2
Cool Aid 6.x Access Bypass / Cross Site Scripting
Posted Feb 29, 2012
Authored by Ivo Van Geertruyen | Site drupal.org

Cool Aid version 6.x suffers from access bypass and cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
SHA-256 | ceaebd230146d69ac1a7302356242e64c1ac00d8647db62d251525c7328404fd
MediaFront 6.x / 7.x Cross Site Scripting
Posted Feb 29, 2012
Authored by Oscar Estepa | Site drupal.org

MediaFront versions 6.x / 7.x suffer from a cross site scripting vulnerability.

tags | advisory, xss
SHA-256 | a63b9fbc20dc44405b79e7f717e234f5e14aec187385aa611dc39a17d0ed1753
Drupal 7.0 Shell Execution
Posted Apr 10, 2011
Authored by KedAns-Dz

Drupal version 7.0 suffers from a remote command execution vulnerability.

tags | exploit, remote
SHA-256 | ae379d3ee6258d3421cda34112b5c194d06dfda66bb8a74d6d48cea995174149
Drupal Broken Anti-Automation / Path Disclosure
Posted Feb 16, 2011
Authored by MustLive

Drupal versions 6.20 and below suffer from broken anti-automation and path disclosure vulnerabilities.

tags | advisory, vulnerability
SHA-256 | 998d6854d0553d84a23f01ebfab42858ac12d515cef3a3c74af722f5b84febca
Drupal CAPTCHA Logic Security Flaw
Posted Feb 10, 2011
Authored by Michele Orru

This is a proof of concept to demonstrate a logic security flow in the way Drupal CAPTCHA is used to protect login forms from bruteforce. If the CAPTCHA challenge is solved, the next login attempts can be issued without solving any new CAPTCHA challenge.

tags | exploit, proof of concept
SHA-256 | da7f99e45b5a53895b8bd9dac1825527757ca21c77e749a8c8a3b52db4fe457e
Drupal XSS Password Changer
Posted Mar 6, 2009
Authored by Justin C. Klein Keane

Small write up regarding a cross site scripting vulnerability on Drupal version 5.15 being used for a password change attack. Attack script included.

tags | exploit, xss
SHA-256 | 86d13cf8462beb1f49b6073cfa700d5ee7e151e78aed8e8844279904e36a02a9
Drupal 6.9 Local File Inclusion
Posted Feb 9, 2009
Authored by Rasool Nasr | Site ircrash.com

Drupal CMS version 6.9 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | 5ea5742e4c37b7cd2fba33b966d49483cb707234194c972941c189554b8419e3
drupal-hijack.txt
Posted Sep 20, 2008
Authored by Hanno Boeck | Site hboeck.de

Drupal CMS fails to set the secure flag in the session cookie allowing for session hijacking.

tags | advisory
advisories | CVE-2008-3661
SHA-256 | 6d5d4657228cd6039e3ccbfbac2cd8adc8cdb25a11f076f03f379e89ca0016db
drupal-hash.txt
Posted Oct 11, 2007
Authored by ShAnKaR | Site securityvulns.com

Drupal versions 5.2 and below PHP Zend Hash vulnerability exploitation vector.

tags | exploit, php
SHA-256 | e0ceb8a054f3c90526912645c8617d496ab9245d1bba15d01bd4e70137ae76dc
Page 3 of 4
Back1234Next

File Archive:

December 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    11 Files
  • 2
    Dec 2nd
    0 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    32 Files
  • 5
    Dec 5th
    10 Files
  • 6
    Dec 6th
    13 Files
  • 7
    Dec 7th
    23 Files
  • 8
    Dec 8th
    19 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close