NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27956  CVE-2015-7304  Cross-site scripting (XSS) vulnerability in the amoCRM module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP POST data.    2.6  Low  2017-01-19  2015-09-22  View
27957  CVE-2015-7305  The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to fields, which allows remote attackers to obtain sensitive atom property information via vectors involving a "debug context."    Medium  2017-01-19  2015-09-22  View
27958  CVE-2015-7306  The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.    4.9  Medium  2017-01-19  2015-09-22  View
27959  CVE-2015-7307  Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.    4.3  Medium  2017-01-19  2015-09-22  View
27960  CVE-2015-7309  The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.    6.5  Medium  2017-01-19  2015-09-23  View

Page 14915 of 17672, showing 5 records out of 88360 total, starting on record 74571, ending on 74575

Actions