Quicksketch Filefield 6.x-3.1 for Drupal

CPE Details

Quicksketch Filefield 6.x-3.1 for Drupal
6.x-3.1
2023-12-28
15h46 +00:00
2023-12-28
15h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:quicksketch:filefield:6.x-3.1:*:*:*:*:drupal:*:*

Informations

Vendor

quicksketch

Product

filefield

Version

6.x-3.1

Target Software

drupal

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2010-1958 2010-06-21 17h00 +00:00 Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).
2.1
CVE-2009-3781 2009-10-26 16h00 +00:00 The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.
7.5