Application: Drupal
Affected Version: versions prior to 5.x-2.1
Vendor’s URL: Email Verification Module
Bug Type: Security Bypass and Cross Site Scripting
Risk Level: Critical
Solution:
Update to version 5.x-2.1 or 6.x-1.2.
Access Bypass, Content Management, Cross Site Scripting
Application: Coppermine Photo Gallery
Affected Version: version 1.4.22 and other versions.
Vendor’s URL: Coppermine Photo Gallery
Bug Type: SQL Injection and System access
Risk Level: Critical
Solution:
Set “magic_quotes_gpc” to “On” and “register_globals” to “Off”.
Access Bypass, Image Galleries, SQL Injection
Application: Drupal
Affected Version: prior to version 5.x-2.0-beta4 and 6.x prior to version 6.x-2.0-beta6.
Vendor’s URL: Drupal
Bug Type: Security Bypass
Risk Level: Medium
Solution:
The security issue is fixed in version 5.x-2.0-beta4 and 6.x-2.0-beta6.
http://drupal.org/node/448390
http://drupal.org/node/448392
Access Bypass, Content Management