Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

nvd логотип

CVE-2013-4174

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flash_width, or (3) flash_height in the scald_flash_scald_prerender function in providers/scald_flash/scald_flash.module; or the (4) caption in the scald_image_scald_prerender function in providers/scald_image/scald_image.module.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-4140

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the TinyBox (Simple Splash) module before 7.x-2.2 for Drupal allows remote authenticated users with the "administer tinybox" permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-2122

больше 12 лет назад

The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-1908

больше 12 лет назад

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-1907

больше 12 лет назад

The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0246

больше 12 лет назад

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-0246

больше 12 лет назад

The Image module in Drupal 7.x before 7.19, when a private file system ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0245

больше 12 лет назад

The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2013-0245

больше 12 лет назад

The printer friendly version functionality in the Book module in Drupa ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2013-0246

больше 12 лет назад

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-4174

Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flash_width, or (3) flash_height in the scald_flash_scald_prerender function in providers/scald_flash/scald_flash.module; or the (4) caption in the scald_image_scald_prerender function in providers/scald_image/scald_image.module.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4140

Cross-site scripting (XSS) vulnerability in the TinyBox (Simple Splash) module before 7.x-2.2 for Drupal allows remote authenticated users with the "administer tinybox" permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-2122

The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary comments of other users via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-1908

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-1907

The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

CVSS2: 5
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0246

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0246

The Image module in Drupal 7.x before 7.19, when a private file system ...

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0245

The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-0245

The printer friendly version functionality in the Book module in Drupa ...

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-0246

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться