VendorsDrupallogintoboggan_moduleall versions
Vulnerabilities

Drupal Logintoboggan Module

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2007-3817
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the username by removing certain characters, so this might not be a vulnerability on default installations.
Published 2007-07-17 · Modified
4.3EPSS 0.012
CVE-2007-3818
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission to inject arbitrary JavaScript and gain privileges via "the message displayed above the default user login block."
Published 2007-07-17 · Modified
3.5EPSS 0.007