Description
Multiple serious vulnerabilities have been found in Drupal modules. Malicious users can exploit these vulnerabilities to bypass security restrictions, inject arbitrary code or obtain sensitive information.
Below is a complete list of vulnerabilities
- Open redirect vulnerabilities in Commerce WeDeal, Node basket, Views and Node Invite modules can be exploited remotely via unspecified vectors;
- XSS vulnerabilities in Ajax Timeline, Facebook Album Fetcher, Public Download Count, Taxonomy Tools, Node Access Product, Taxonomy Path, Commerce Balanced Payments, Node basket, Quizzler, Node Invite, Taxonews, Classified Ads, Nodeauthor and Content Analysis modules can be exploited remotely via a specially designed parameters or other unknown vectors;
- Unknown vulnerability in Path Breadcrumbs module can be exploited remotely via a 403 page reading;
- CSRF vulnerabilities in Node basket, Feature Set, Shibboleth Authentication, Corner, Node Invite, Patterns, Alfresco and Contact Form Fields modules can be exploited remotely via an unspecified vectors;
- An improper access restrictions in Views module can be exploited remotely via an unknown vectors;
- Improper token generation in Amazon AWS module can be exploited remotely via an unspecified vectors.
Original advisories
Related products
CVE list
- CVE-2015-3393 high
- CVE-2015-3392 warning
- CVE-2015-3391 critical
- CVE-2015-3390 warning
- CVE-2015-3389 warning
- CVE-2015-3388 high
- CVE-2015-3387 warning
- CVE-2015-3386 warning
- CVE-2015-3385 warning
- CVE-2015-3384 warning
- CVE-2015-3383 high
- CVE-2015-3382 high
- CVE-2015-3381 warning
- CVE-2015-3380 high
- CVE-2015-3379 warning
- CVE-2015-3378 warning
- CVE-2015-3376 warning
- CVE-2015-3375 high
- CVE-2015-3374 high
- CVE-2015-3373 critical
- CVE-2015-3372 warning
- CVE-2015-3371 high
- CVE-2015-3370 high
- CVE-2015-3369 warning
- CVE-2015-3368 warning
- CVE-2015-3367 high
- CVE-2015-3366 high
- CVE-2015-3365 warning
- CVE-2015-3364 warning
- CVE-2015-3363 high
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!