Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

nvd логотип

CVE-2012-5651

больше 13 лет назад

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-5651

больше 13 лет назад

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for bl ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-5651

больше 13 лет назад

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-5653

больше 13 лет назад

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2012-5652

больше 13 лет назад

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-5591

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the Zero Point module 6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the path aliases.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-5590

больше 13 лет назад

SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-5589

больше 13 лет назад

The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-5588

больше 13 лет назад

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-5587

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto link.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

CVSS2: 5
3%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for bl ...

CVSS2: 5
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

CVSS2: 5
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5653

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

CVSS2: 6
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5652

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

CVSS2: 5
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5591

Cross-site scripting (XSS) vulnerability in the Zero Point module 6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the path aliases.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5590

SQL injection vulnerability in the Webmail Plus module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5589

The MultiLink module 6.x-2.x before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal does not properly check node permissions when generating an in-content link, which allows remote authenticated users with text-editing permissions to read arbitrary node titles via a generated link.

CVSS2: 3.5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5588

The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly check permissions, which allows remote attackers to email the stored address via unspecified vectors.

CVSS2: 2.6
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5587

Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto link.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться