Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

debian логотип

CVE-2013-0316

больше 13 лет назад

The Image module in Drupal 7.x before 7.20 allows remote attackers to ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0260

больше 13 лет назад

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0259

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0258

больше 13 лет назад

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-0257

больше 13 лет назад

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0182

больше 13 лет назад

The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0181

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2013-0316

больше 13 лет назад

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0227

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0225

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-0316

The Image module in Drupal 7.x before 7.20 allows remote attackers to ...

CVSS2: 5
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0260

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0259

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 2.1
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0258

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0257

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

CVSS2: 5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0182

The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.

CVSS2: 5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0181

Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.

CVSS2: 2.6
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2013-0316

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

CVSS2: 5
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0227

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

CVSS2: 2.1
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0225

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

CVSS2: 2.1
1%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться