Services project Services for Drupal 7.x-3.0

CPE Details

Services project Services for Drupal 7.x-3.0
7.x-3.0
2015-06-16
15h16 +00:00
2015-07-28
10h41 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:services_project:services:7.x-3.0:*:*:*:*:drupal:*:*

Informations

Vendor

services_project

Product

services

Version

7.x-3.0

Target Software

drupal

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2015-4393 2015-06-15 12h00 +00:00 The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.
6
CVE-2015-4394 2015-06-15 12h00 +00:00 The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified vectors.
5
CVE-2014-9152 2014-12-01 16h00 +00:00 The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
7.5
CVE-2013-2158 2013-07-01 19h00 +00:00 Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
6.8