This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:drupal:drupal:4.6.5 |
| Detail | |||
|---|---|---|---|
| Vendor | Drupal | First view | 2006-03-14 |
| Product | Drupal | Last view | 2012-03-28 |
| Version | 4.6.5 | Type | Application |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/a:drupal:drupal | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 6.8 | 2012-03-28 | CVE-2007-6752 | Network | Medium | None Requ... | |
| 4.3 | 2008-01-15 | CVE-2008-0276 | Network | Medium | None Requ... | |
| 4.3 | 2008-01-15 | CVE-2008-0273 | Network | Medium | None Requ... | |
| 4.3 | 2008-01-15 | CVE-2008-0272 | Network | Medium | None Requ... | |
| 7.5 | 2007-12-10 | CVE-2007-6299 | Network | Low | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 3.5 | 2007-01-08 | CVE-2007-0124 | Network | Medium | Requires ... | |
| 2.6 | 2006-10-24 | CVE-2006-5477 | Network | High | None Requ... | |
| 7.5 | 2006-10-24 | CVE-2006-5476 | Network | Low | None Requ... | |
| 6.8 | 2006-10-24 | CVE-2006-5475 | Network | Medium | None Requ... | |
| 4.3 | 2006-08-07 | CVE-2006-4002 | Network | Medium | None Requ... | |
| 2.6 | 2006-06-05 | CVE-2006-2832 | Network | High | None Requ... | |
| 7.5 | 2006-06-05 | CVE-2006-2831 | Network | Low | None Requ... | |
| 5.1 | 2006-06-01 | CVE-2006-2743 | Network | High | None Requ... | |
| 7.5 | 2006-06-01 | CVE-2006-2742 | Network | Low | None Requ... | |
| 4.6 | 2006-03-14 | CVE-2006-1227 | Local | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 33% (2) | CWE-352 | Cross-Site Request Forgery (CSRF) |
| 33% (2) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 16% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
| 16% (1) | CWE-20 | Improper Input Validation |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 42164 | Drupal Browser Interpretation Conflict (MSIE 6) UTF-8 XSS |
| 42163 | Drupal Aggregator Module CSRF Feed Item Deletion |
| 42023 | Devel Module for Drupal site Parameter XSS |
| 39649 | Drupal taxonomy_select_nodes() Function SQL Injection |
| 32131 | Drupal Page Cache Poisoning 404 Page DoS |
| id | Description |
|---|---|
| 29927 | Drupal Form Action Attribute Injection |
| 29926 | Drupal Unspecified CSRF |
| 29922 | Drupal XML Parser RSS Feed XSS |
| 27754 | Drupal user.module msg Parameter XSS |
| 27595 | Drupal upload.module Filename XSS |
| 27593 | Drupal database.mysqli.inc Multiple Parameter SQL Injection |
| 27592 | Drupal database.pgsql.inc Multiple Parameter SQL Injection |
| 25910 | Drupal File Upload Multiple Extension Restriction Bypass |
| 25909 | Drupal on Apache files Directory File Upload Arbitrary Code Execution |
| 25908 | Drupal database.mysql.inc Multiple Parameter SQL Injection |
| 23909 | Drupal menu.module Menu Item Creation Page Restriction Bypass |
Milw0rm Exploits
| id | Description |
|---|---|
| 2006-05-24 | Drupal <= 4.7 (attachment mod_mime) Remote Exploit |








