Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

ubuntu логотип

CVE-2010-5312

около 11 лет назад

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2014-9016

около 11 лет назад

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2014-9016

около 11 лет назад

The password hashing API in Drupal 7.x before 7.34 and the Secure Pass ...

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2014-9015

около 11 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-9015

около 11 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9016

около 11 лет назад

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2014-9015

около 11 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-3704

больше 11 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
EPSS: Критический
debian логотип

CVE-2014-3704

больше 11 лет назад

The expandArguments function in the database abstraction API in Drupal ...

CVSS2: 7.5
EPSS: Критический
ubuntu логотип

CVE-2014-3704

больше 11 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2010-5312

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

CVSS3: 6.1
5%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

CVSS2: 5
80%
Высокий
около 11 лет назад
debian логотип
CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Pass ...

CVSS2: 5
80%
Высокий
около 11 лет назад
nvd логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
2%
Низкий
около 11 лет назад
debian логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVSS2: 6.8
2%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

CVSS2: 5
80%
Высокий
около 11 лет назад
ubuntu логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
94%
Критический
больше 11 лет назад
debian логотип
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal ...

CVSS2: 7.5
94%
Критический
больше 11 лет назад
ubuntu логотип
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
94%
Критический
больше 11 лет назад

Уязвимостей на страницу


Поделиться