Vulnerabilities
Vulnerable Software
Ezra Barnett Gildesgame:  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in the Subgroups for Organic Groups (OG) module 5.x before 5.x-4.0 and 5.x before 5.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified node titles.
CVSS Score
4.3
EPSS Score
0.004
Published
2009-11-24
The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node privileges in certain circumstances involving subqueue creation, which allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.
CVSS Score
4.0
EPSS Score
0.004
Published
2009-11-09


Contact Us

Shodan ® - All rights reserved