NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27956 | CVE-2015-7304 | Cross-site scripting (XSS) vulnerability in the amoCRM module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP POST data. | 2 | 2.6 | Low | 2017-01-19 | 2015-09-22 | View | |
| 27957 | CVE-2015-7305 | The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to fields, which allows remote attackers to obtain sensitive atom property information via vectors involving a "debug context." | 2 | 5 | Medium | 2017-01-19 | 2015-09-22 | View | |
| 27958 | CVE-2015-7306 | The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission. | 2 | 4.9 | Medium | 2017-01-19 | 2015-09-22 | View | |
| 27959 | CVE-2015-7307 | Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page. | 2 | 4.3 | Medium | 2017-01-19 | 2015-09-22 | View | |
| 27960 | CVE-2015-7309 | The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it. | 2 | 6.5 | Medium | 2017-01-19 | 2015-09-23 | View |
Page 14915 of 17672, showing 5 records out of 88360 total, starting on record 74571, ending on 74575