Vulnerabilities (CVE)

Filtered by vendor Unleashedmind Subscribe
Filtered by product Img Assist
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4558 2 Drupal, Unleashedmind 2 Drupal, Img Assist 2024-02-28 5.0 MEDIUM N/A
The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body of an arbitrary node via unknown vectors.
CVE-2009-4557 2 Drupal, Unleashedmind 2 Drupal, Img Assist 2024-02-28 2.1 LOW N/A
Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, allows remote authenticated users, with image-node creation privileges, to inject arbitrary web script or HTML via a node title.