Contrib security advisories
SA-CONTRIB-2010-089 - Simplenews Content Selection - Cross Site Scripting
- Advisory ID: DRUPAL-SA-CONTRIB-2010-089
- Project: Simplenews content selection (third-party module)
- Version: 6.x
- Date: 2010-August-18
- Security risk: Less critical
- Exploitable from: Remote
- Vulnerability: Cross site scripting
Categories: Security
SA-CONTRIB-2010-088 - Content Construction Kit (CCK) - Access Bypass
- Advisory ID: DRUPAL-SA-CONTRIB-2010-088
- Project: Content Construction Kit (CCK) (third-party module)
- Version: 6.x
- Date: 2010-August-11
- Security risk: Less Critical
- Exploitable from: Remote
- Vulnerability: Access Bypass
Categories: Security
SA-CONTRIB-2010-087 - GovDelivery - Cross site scripting
- Advisory ID: DRUPAL-SA-CONTRIB-2010-087
- Project: GovDelivery Integration (third-party module)
- Version: 6.x
- Date: 2010-Aug-11
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross site scripting
Categories: Security
SA-CONTRIB-2010-086 - Prepopulate - Access Bypass
- Advisory ID: DRUPAL-SA-CONTRIB-2010-086
- Project: Prepopulate (third-party module)
- Version: 5.x and 6.x
- Date: 2010-Aug-11
- Security risk: Moderately Critical
- Exploitable from: Remote
- Vulnerability: Access Bypass
Categories: Security
SA-CONTRIB-2010-085 - Pathauto - Cross Site Scripting
- Advisory ID: DRUPAL-SA-CONTRIB-2010-085
- Project: Pathauto (third-party module)
- Version: 5.x, 6.x
- Date: 2010-August-11
- Security risk: Less critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Categories: Security
SA-CONTRIB-2010-084 - OpenID - Authentication bypass
- Advisory ID: DRUPAL-SA-CONTRIB-2010-084
- Project: OpenID (third-party module)
- Version: 5.x
- Date: 2010-Aug-11
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Authentication bypass
Categories: Security
SA-CONTRIB-2010-083 - Ubercart sub-modules - Multiple Vulnerabilities
- Advisory ID: DRUPAL-SA-CONTRIB-2010-083
- Project: UC2Checkout, UCPaypal, UC Cart LInks (third-party modules in the Ubercart Project)
- Version: 5.x, 6.x
- Date: 2010-Aug-11
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Access Bypass, Cross Site Request Forgery
Categories: Security
SA-CONTRIB-2010-082 - Print - Local file read access
- Advisory ID: DRUPAL-SA-CONTRIB-2010-082
- Project: Printer, e-mail and PDF versions (third-party module)
- Version: 5.x, 6.x
- Date: 2010-August-11
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Local file read access
Categories: Security
SA-CONTRIB-2010-081 - FileField Sources - Arbitrary Code Execution
- Advisory ID: DRUPAL-SA-CONTRIB-2010-081
- Project: FileField Sources (third-party module)
- Version: 6.x
- Date: 2010-May-19
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Arbitrary Code Execution
Categories: Security
SA-CONTRIB-2010-080 - Privatemsg - Cross Site Scripting
- Advisory ID: DRUPAL-SA-CONTRIB-2010-080
- Project: Privatemsg (third-party module)
- Version: 6.x
- Date: 2010-August-11
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross-Site Scripting
Categories: Security
SA-CONTRIB-2010-079 - Devel (Performance logging) - Cross Site Scripting
- Advisory ID: SA-CONTRIB-2010-079
- Project: Devel (third-party module)
- Version: 5.x, 6.x
- Date: 2010-Aug-04
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Categories: Security
SA-CONTRIB-2010-078 - Kaltura - Information disclosure
- Advisory ID: DRUPAL-SA-CONTRIB-2010-078
- Project: Kaltura (third-party module)
- Versions: 5.x, 6.x
- Date: 2010-July-28
- Security risk: Less Critical
- Exploitable from: Remote
- Vulnerability: Information disclosure
Categories: Security
SA-CONTRIB-2010-077 - Sage Pay (former Protx) Direct Payment Gateway for Ubercart - Information Disclosure
- Advisory ID: DRUPAL-SA-CONTRIB-2010-077
- Project: Sage Pay Direct Payment Gateway for Ubercart (third-party module)
- Version: 5.x, 6.x
- Date: 2010-July-28
- Security risk: Less Critical
- Exploitable from: Remote
- Vulnerability: Information Disclosure
Categories: Security
SA-CONTRIB-2010-076 - Dashboard - Cross Site Scripting (CSS)
- Advisory ID: SA-CONTRIB-2010-076
- Project: Dashboard (third-party module)
- Version: 6.x
- Date: 2010-July-28
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Categories: Security
SA-CONTRIB 2010-075 - Tagging - Cross Site Scripting
- Advisory ID: DRUPAL-SA-CONTRIB-2010-075
- Project: Tagging (third-party module)
- Version: 6.x
- Date: 2010-July 21
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Categories: Security
SA-CONTRIB-2010-074 - Drupad - Cross-site request forgery
- Advisory ID: DRUPAL-SA-CONTRIB-2010-074
- Projects: Drupad (third-party module)
- Version: 6.x
- Date: 2010-07-14
- Security risks: Critical
- Exploitable from: Remote
- Vulnerability: CSRF
Categories: Security
SA-CONTRIB-2010-073 - Multiple Vulnerabilities In Multiple Contributed Modules
- Advisory ID: DRUPAL-SA-CONTRIB-2010-073
- Projects: Multiple third party modules - Simple Gallery, OG Menu, Tell A Friend Node, JsMath For Displaying Mathematics With TeX
- Version: 5.x, 6.x
- Date: 2010-July-14
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Multiple (Cross Site Scripting, Email Header Injection)
Categories: Security
SA-CONTRIB-2010-072: Hierarchical Select - Cross Site Scripting
- Advisory ID: DRUPAL-SA-CONTRIB-2010-0XX
- Project: Hierarchical Select (third-party module)
- Version: 5.x, 6.x
- Date: 2010-July-07
- Security risk: Moderately critical
- Exploitable from: Remote
- Vulnerability: Cross Site Scripting
Categories: Security
SA-CONTRIB-2010-071 - MultiSafepay Integration - Cross Site Request Forgery
- Advisory ID: DRUPAL-SA-CONTRIB-2010-071
- Project: MultiSafepay Integration (third-party module)
- Version: 6.x
- Date: 2010-July-07
- Security risk: Critical
- Exploitable from: Remote
- Vulnerability: Cross Site Request Forgery
Categories: Security
SA-CONTRIB-2010-070 - Multiple vulnerabilities in multiple contributed modules
- Advisory ID: DRUPAL-SA-CONTRIB-2010-070
- Projects: Multiple third party modules - Easy Translator, Block Queue, Multiple Image Upload (Imagex)
- Version: 5.x, 6.x
- Date: 2010-06-23
- Security risks: Critical
- Exploitable from: Remote
- Vulnerability: Multiple (SQL Injection, CSRF, Access bypass)
Categories: Security

