Services project Services for Drupal 7.x-3.9

CPE Details

Services project Services for Drupal 7.x-3.9
7.x-3.9
2014-12-01
18h04 +00:00
2015-01-12
18h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:services_project:services:7.x-3.9:*:*:*:*:drupal:*:*

Informations

Vendor

services_project

Product

services

Version

7.x-3.9

Target Software

drupal

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2015-4393 2015-06-15 12h00 +00:00 The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.
6
CVE-2014-9151 2014-12-01 16h00 +00:00 The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
7.5
CVE-2014-9152 2014-12-01 16h00 +00:00 The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.
7.5
CVE-2014-9153 2014-12-01 16h00 +00:00 Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response.
4.3