Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch7c-r59p-c6q5

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

EPSS

Процентиль: 47%
0.00236
Низкий

Связанные уязвимости

ubuntu
почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

nvd
почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

debian
почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ...

EPSS

Процентиль: 47%
0.00236
Низкий