Justin Dodge Hotblocks module for Drupal 6.x-1.7

CPE Details

Justin Dodge Hotblocks module for Drupal 6.x-1.7
6.x-1.7
2012-11-01
16h48 +00:00
2012-11-21
16h17 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:justin_dodge:hotblocks:6.x-1.7:*:*:*:*:*:*:*

Informations

Vendor

justin_dodge

Product

hotblocks

Version

6.x-1.7

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2012-5704 2012-11-01 10h00 +00:00 The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a block that references itself.
3.5
CVE-2012-5705 2012-11-01 10h00 +00:00 Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names."
2.1