Skip to main content

Vendor/product archive

marc_ingram / services CVEs

Beta · best-effort

4 CVEs tagged to marc_ingram / services0 Critical, 2 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2012-5586

Published Dec 26, 2012

The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary u…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-6910

Published Aug 6, 2009

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6909

Published Aug 6, 2009

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6908

Published Aug 6, 2009

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1