Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

ubuntu логотип

CVE-2013-6385

больше 12 лет назад

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2013-6389

больше 12 лет назад

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-4446

больше 12 лет назад

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-4445

больше 12 лет назад

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2012-0827

почти 13 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-0827

почти 13 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-0826

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0826

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0825

почти 13 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0825

почти 13 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2013-6385

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

CVSS2: 5.1
3%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6389

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 5.8
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4446

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4445

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for remote authenticated users to guess the access token for a block by leveraging the token from a block to which the user has access.

CVSS2: 4.9
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVSS2: 3.5
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVSS2: 6.8
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVSS2: 6.8
2%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться