Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 029
CVE-2010-5312
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the ...
CVE-2010-5312
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
CVE-2014-9016
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
CVE-2014-9016
The password hashing API in Drupal 7.x before 7.34 and the Secure Pass ...
CVE-2014-9015
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
CVE-2014-9015
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...
CVE-2014-9016
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
CVE-2014-9015
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2010-5312 Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the ... | CVSS3: 6.1 | 18% Средний | больше 11 лет назад | |
CVE-2010-5312 Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option. | CVSS3: 6.1 | 18% Средний | больше 11 лет назад | |
CVE-2014-9016 The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | CVSS2: 5 | 82% Высокий | больше 11 лет назад | |
CVE-2014-9016 The password hashing API in Drupal 7.x before 7.34 and the Secure Pass ... | CVSS2: 5 | 82% Высокий | больше 11 лет назад | |
CVE-2014-9015 Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions. | CVSS2: 6.8 | 2% Низкий | больше 11 лет назад | |
CVE-2014-9015 Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ... | CVSS2: 6.8 | 2% Низкий | больше 11 лет назад | |
CVE-2014-9016 The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request. | CVSS2: 5 | 82% Высокий | больше 11 лет назад | |
CVE-2014-9015 Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions. | CVSS2: 6.8 | 2% Низкий | больше 11 лет назад | |
CVE-2014-3704 The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | CVSS2: 7.5 | 100% Критический | почти 12 лет назад | |
CVE-2014-3704 The expandArguments function in the database abstraction API in Drupal ... | CVSS2: 7.5 | 100% Критический | почти 12 лет назад |
Уязвимостей на страницу