Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 988
CVE-2012-1636
Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified vectors.
CVE-2012-1639
Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.
CVE-2012-2153
Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.
CVE-2012-2153
Drupal 7.x before 7.14 does not properly restrict access to nodes in a ...
CVE-2012-1591
The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.
CVE-2012-1591
The image module in Drupal 7.x before 7.14 does not properly check per ...
CVE-2012-1590
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.
CVE-2012-1590
The forum list in Drupal 7.x before 7.14 does not properly check user ...
CVE-2012-1588
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.
CVE-2012-1588
Algorithmic complexity vulnerability in the _filter_url function in th ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2012-1636 Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified vectors. | CVSS2: 4.3 | 0% Низкий | больше 13 лет назад | |
CVE-2012-1639 Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters. | CVSS2: 3.5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2153 Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page. | CVSS2: 4 | 0% Низкий | больше 13 лет назад | |
CVE-2012-2153 Drupal 7.x before 7.14 does not properly restrict access to nodes in a ... | CVSS2: 4 | 0% Низкий | больше 13 лет назад | |
CVE-2012-1591 The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles. | CVSS2: 5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-1591 The image module in Drupal 7.x before 7.14 does not properly check per ... | CVSS2: 5 | 0% Низкий | больше 13 лет назад | |
CVE-2012-1590 The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | CVSS2: 4 | 0% Низкий | больше 13 лет назад | |
CVE-2012-1590 The forum list in Drupal 7.x before 7.14 does not properly check user ... | CVSS2: 4 | 0% Низкий | больше 13 лет назад | |
CVE-2012-1588 Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address. | CVSS2: 3.5 | 1% Низкий | больше 13 лет назад | |
CVE-2012-1588 Algorithmic complexity vulnerability in the _filter_url function in th ... | CVSS2: 3.5 | 1% Низкий | больше 13 лет назад |
Уязвимостей на страницу