Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

debian логотип

CVE-2014-2983

больше 12 лет назад

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate t ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-2983

больше 12 лет назад

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-1946

больше 12 лет назад

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4383

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-1611

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1607

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1476

больше 12 лет назад

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2014-1476

больше 12 лет назад

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an e ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2014-1475

больше 12 лет назад

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-1475

больше 12 лет назад

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-2983

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate t ...

CVSS2: 5
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2983

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

CVSS2: 5
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-1946

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4383

Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1611

Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1607

Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1476

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.

CVSS2: 4
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1476

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an e ...

CVSS2: 4
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1475

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

CVSS2: 7.5
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1475

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows ...

CVSS2: 7.5
2%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться