This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Chaos Tool Suite Project First view 2010-05-21
Product Ctools Last view 2017-08-07
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.2:*:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.1:*:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:alpha2:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:alpha3:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.3:*:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.x:dev:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:beta3:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:beta4:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:beta1:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:beta2:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:*:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:alpha1:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.0:rc1:*:*:*:drupal:*:* 8
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.6:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.4:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.5:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.9:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.8:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.7:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.1:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.2:*:*:*:*:drupal:*:* 4
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.6:*:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.4:*:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.5:*:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.3:*:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.11:*:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.x:dev:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha1:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:beta1:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha4:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:rc2:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:rc1:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha3:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.0:alpha2:*:*:*:drupal:*:* 3
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.6:rc1:*:*:*:drupal:*:* 2
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.12:*:*:*:*:drupal:*:* 2
cpe:2.3:a:chaos_tool_suite_project:ctools:6.x-1.13:*:*:*:*:drupal:*:* 2
cpe:2.3:a:chaos_tool_suite_project:ctools:7.x-1.7:*:*:*:*:drupal:*:* 1

Related : CVE

  Date Alert Description
7.5 2017-08-07 CVE-2015-7875

ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.

4.3 2015-08-24 CVE-2015-6665

Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.

5.8 2015-06-16 CVE-2015-4398

Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.

4.3 2015-06-15 CVE-2015-4375

The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities without an access query tag or (2) leveraging knowledge of the ID of an entity.

3.5 2013-07-16 CVE-2013-1925

The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" permission to read restricted node titles via an autocomplete list.

2.6 2012-12-03 CVE-2012-5559

Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.

2.1 2012-08-14 CVE-2012-2082

Cross-site scripting (XSS) vulnerability in the Chaos tool suite (aka CTools) module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the post comments permission to inject arbitrary web script or HTML via a user signature.

4.3 2010-05-21 CVE-2010-2010

Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.

3.5 2010-05-21 CVE-2010-1548

The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated users, with "access content" privileges, to read the title of an unpublished node via a q=ctools/autocomplete/node/ value accompanied by the first character of the node's title.

6.8 2010-05-21 CVE-2010-1547

Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable a page via a q=admin/build/pages/nojs/enable/ value or (2) disable a page via a q=admin/build/pages/nojs/disable/ value.

6 2010-05-21 CVE-2010-1546

Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with "administer page manager" privileges, to execute arbitrary PHP code via input to a text area, related to (1) the page_manager_page_import_subtask_validate function in page_manager/plugins/tasks/page.admin.inc and (2) the page_manager_handler_import_validate function in page_manager/page_manager.admin.inc.

CWE : Common Weakness Enumeration

%idName
40% (4) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
30% (3) CWE-264 Permissions, Privileges, and Access Controls
10% (1) CWE-352 Cross-Site Request Forgery (CSRF)
10% (1) CWE-200 Information Exposure
10% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')

Open Source Vulnerability Database (OSVDB)

id Description
64767 Chaos Tool Suite Module for Drupal ctools/autocomplete/node URI Access Restri...
64766 Chaos Tool Suite Module for Drupal Administrative Forms CSRF
64765 Chaos Tool Suite Module for Drupal admin/build/pages object Parameter Arbitra...
64764 Chaos Tool Suite Module for Drupal admin/build/pages/import object Parameter ...
64763 Chaos Tool Suite Module for Drupal Node Titles XSS

OpenVAS Exploits

id Description
2012-12-14 Name : Fedora Update for drupal6-ctools FEDORA-2012-19449
File : nvt/gb_fedora_2012_19449_drupal6-ctools_fc16.nasl
2012-12-14 Name : Fedora Update for drupal6-ctools FEDORA-2012-19464
File : nvt/gb_fedora_2012_19464_drupal6-ctools_fc17.nasl

Nessus® Vulnerability Scanner

id Description
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-13916.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-13917.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-14329.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-14330.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-14331.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-14442.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-14443.nasl - Type: ACT_GATHER_INFO
2015-09-08 Name: The remote Fedora host is missing a security update.
File: fedora_2015-14444.nasl - Type: ACT_GATHER_INFO
2015-09-02 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3346.nasl - Type: ACT_GATHER_INFO
2015-08-28 Name: The remote Fedora host is missing a security update.
File: fedora_2015-13915.nasl - Type: ACT_GATHER_INFO
2015-08-26 Name: The remote web server is running a PHP application that is affected by multip...
File: drupal_7_39.nasl - Type: ACT_GATHER_INFO
2013-01-14 Name: The remote Fedora host is missing a security update.
File: fedora_2012-19508.nasl - Type: ACT_GATHER_INFO
2012-12-13 Name: The remote Fedora host is missing a security update.
File: fedora_2012-19449.nasl - Type: ACT_GATHER_INFO
2012-12-13 Name: The remote Fedora host is missing a security update.
File: fedora_2012-19464.nasl - Type: ACT_GATHER_INFO