NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26651 | CVE-2015-5512 | The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26650 | CVE-2015-5511 | The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login. | 2 | 5 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26649 | CVE-2015-5510 | Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration pages. | 2 | 5.8 | Medium | 2017-01-19 | 2015-09-03 | View | |
| 26648 | CVE-2015-5509 | The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors. | 2 | 6 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 26647 | CVE-2015-5508 | Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request. | 2 | 5.1 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 3024 of 17672, showing 5 records out of 88360 total, starting on record 15116, ending on 15120