NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25802  CVE-2015-4344  The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.    Medium  2017-01-19  2016-06-09  View
25803  CVE-2015-4345  The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors.    Medium  2017-01-19  2016-06-09  View
25804  CVE-2015-4346  Cross-site scripting (XSS) vulnerability in the SMS Framework module 6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to message previews.    2.6  Low  2017-01-19  2015-06-30  View
25805  CVE-2015-4347  Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified path arguments.    4.3  Medium  2017-01-19  2015-06-30  View
25806  CVE-2015-4348  SQL injection vulnerability in the Spider Contacts module for Drupal allows remote authenticated users with the "access Spider Contacts category administration" permission to execute arbitrary SQL commands via unspecified vectors.    Medium  2017-01-19  2015-06-30  View

Page 14475 of 17672, showing 5 records out of 88360 total, starting on record 72371, ending on 72375

Actions