rigadicomando.org

Whatever you can cat

Random Quote

Being and non-being produce each other.
Difficult and easy complement each other.
Long and short define each other.
High and low oppose each other.
Fore and aft follow each other.

• Lao Tzu

Secondary links

  • About
  • Contacts
  • Disclaimer

Home News aggregator Sources

Drupal Security

Syndicate content
This list is for security announcements sent out be the Drupal security team.
URL: http://drupal.org/taxonomy/term/44/0
Updated: 4 hours 7 min ago

SA-2008-048 - CCK - Cross site scripting

Thu, 2008-09-04 19:43
  • Advisory ID: DRUPAL-SA-2008-048
  • Project: CCK (third-party module)
  • Version: 5.x
  • Date: 2008-Sep-04
  • Security risk: Not critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: CMS

SA-2008-047 - Drupal core - Multiple vulnerabilities

Wed, 2008-08-13 23:27
  • Advisory ID: DRUPAL-SA-2008-047
  • Project: Drupal core
  • Version: 5.x, 6.x
  • Date: 2008-August-13
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

read more

Categories: CMS

SA-2008-046 - Drupal core - Session fixation

Wed, 2008-07-23 19:58
  • Advisory ID: DRUPAL-SA-2008-046
  • Project: Drupal core
  • Version: 5.x
  • Date: 2008-July-23
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Session fixation

read more

Categories: CMS

SA-2008-045 - OpenID - Multiple vulnerabilities

Wed, 2008-07-09 22:08
  • Advisory ID: DRUPAL-SA-2008-045
  • Project: OpenID (third-party module)
  • Version: 5.x
  • Date: 2008-July-9
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting, Cross site request forgeries

read more

Categories: CMS

SA-2008-044 - Drupal core - Multiple vulnerabilities

Wed, 2008-07-09 21:24
  • Advisory ID: DRUPAL-SA-2008-044
  • Project: Drupal core
  • Version: 5x, 6.x
  • Date: 2008-July-9
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

read more

Categories: CMS

SA-2008-043 - Outline designer - Privilege escalation

Wed, 2008-07-02 20:56
  • Advisory ID: DRUPAL-SA-2008-043
  • Project: Outline designer (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Privilege escalation

read more

Categories: CMS

SA-2008-042 - Tinytax - Cross site scripting

Wed, 2008-07-02 20:51
  • Advisory ID: DRUPAL-SA-2008-042
  • Project: Tinytax taxonomy block (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: CMS

SA-2008-041 - Taxonomy autotagger - Multiple vulnerabilities

Wed, 2008-07-02 20:48
  • Advisory ID: DRUPAL-SA-2008-041
  • Project: Taxonomy autotagger (third-party module)
  • Version: 5.x
  • Date: 2008-July-2
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting and SQL injection

read more

Categories: CMS

SA-2008-040 - Organic Groups - Cross site scripting and information disclosure

Wed, 2008-07-02 20:42
  • Advisory ID: DRUPAL-SA-2008-040
  • Project: Organic Groups (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-July-02
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting and information disclosure

read more

Categories: CMS

SA-2008-039 - Suggested terms - Cross site scripting

Wed, 2008-06-25 18:53
  • Advisory ID: SA-2008-039
  • Project: Suggested terms (third-party module)
  • Versions: 5.x
  • Date: 2008-June-25
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: CMS

SA-2008-038 - Services - Arbitrary code execution

Wed, 2008-06-18 21:50
  • Advisory ID: DRUPAL-SA-2008-038
  • Project: Services (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-June-18
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Arbitrary code execution

read more

Categories: CMS

SA-2008-037 - TrailScout - XSS and SQL injection

Wed, 2008-06-18 21:07
  • Advisory ID: DRUPAL-SA-2008-037
  • Project: TrailScout (third-party module)
  • Version: 5.x
  • Date: 2008-June-18
  • Security risk: Higly critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting and SQL injection

read more

Categories: CMS

SA-2008-036 - Profile search - SQL Injection

Wed, 2008-06-18 15:15
  • Advisory ID: SA-2008-036
  • Project: Profile Search (third-party module)
  • Versions: 5.x
  • Date: 2008-July-18
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

read more

Categories: CMS

SA-2008-035 - Aggregation - Multiple vulnerabilities

Wed, 2008-06-11 19:44
  • Advisory ID: SA-2008-035
  • Project: Aggregation (third-party module)
  • Versions: 5.x
  • Date: 2008-June-11
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities

read more

Categories: CMS

SA-2008-034 - Node Hierarchy - Access bypass

Wed, 2008-06-11 19:24
  • Advisory ID: SA-2008-034
  • Project: Node Hierarchy (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-June-11
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

read more

Categories: CMS

SA-2008-033 - Taxonomy Image - Cross site scripting

Wed, 2008-06-11 16:11
  • Advisory ID: SA-2008-033
  • Project: Taxonomy Image (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-June-11
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting

read more

Categories: CMS

SA-2008-032 - Magic Tabs - Arbitrary code execution

Wed, 2008-06-11 13:16
  • Advisory ID: SA-2008-032
  • Project: Magic Tabs (third-party module)
  • Versions: 5.x
  • Date: 2008-June-11
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability: Arbitrary code execution

read more

Categories: CMS

SA-2008-031 - Pblog - Incorrect vulnerability report

Wed, 2008-06-11 12:31
  • Advisory ID: SA-2008-031
  • Project: Pblog (third-party module)
  • Versions: none
  • Date: 2008-June-11
  • Security risk: Not critical
  • Exploitable from: Remote
  • Subject: Incorrect vulnerability report

read more

Categories: CMS

LinkShare  Referral  Prg

CheapOair.com

tags in Arguments

administrivia bash Debian GNU/Linux OS emacs howto perl scripts web
more tags

Navigation

  • Feedback
  • News aggregator
    • Categories
    • Sources

ICT users' rights

  • FSF and Stephen Fry celebrate the GNU Project 25th anniversary
  • Spring 2008 Bulletin available online
  • Submit your nominations for the 2008 Free Software Awards
  • FSF demonstrates iPhone's incompatibility with free software and GPLv3
  • Atheros releases free software wireless driver; no binary blobs
more

High Scalability Architecture

  • Latency is Everywhere and it Costs You Sales - How to Crush it
  • MapReduce framework Disco
  • What CDN would you recommend?
  • SMACKDOWN :: Who are the Open Source Content Management System (CMS) market leaders in 2008?
  • 37signals Architecture
more

Debian Security

  • DSA-1634 wordnet
  • DSA-1633 slash
  • DSA-1632 tiff
  • DSA-1631 libxml2
  • DSA-1630 linux-2.6
more

Drupal Security

  • SA-2008-048 - CCK - Cross site scripting
  • SA-2008-047 - Drupal core - Multiple vulnerabilities
  • SA-2008-046 - Drupal core - Session fixation
  • SA-2008-045 - OpenID - Multiple vulnerabilities
  • SA-2008-044 - Drupal core - Multiple vulnerabilities
more

EFF

  • FBI Withdraws Unconstitutional National Security Letter After ACLU and EFF Challenge
  • EFF and Sheppard Mullin Defend Wikipedia in Defamation Case
  • Congress Must Investigate Electronic Searches at U.S. Borders
  • Betrayed MSN Music Customers Deserve More from Microsoft
  • EFF Report: FBI Slowed Terror Investigation with Improper NSL Request
more

Invent Geek

  • the ion cooler 2.0
  • the ultimate dance pad v1.0
  • thermaltake sponsors inventgeek
  • The Thermaltake MiniFridge Case Mod
  • Inventgeek gets a facelift and a butt tuck
more

 Privacy | Disclaimer | Drupal | Creative Commons

All content on this site is ditributed under Creative Commons License, each individual author is responsible for its own posts.

RoopleTheme