Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

nvd логотип

CVE-2012-5233

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2012-1636

почти 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-1639

почти 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-2153

почти 14 лет назад

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2153

почти 14 лет назад

Drupal 7.x before 7.14 does not properly restrict access to nodes in a ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-1591

почти 14 лет назад

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-1591

почти 14 лет назад

The image module in Drupal 7.x before 7.14 does not properly check per ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-1590

почти 14 лет назад

The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-1590

почти 14 лет назад

The forum list in Drupal 7.x before 7.14 does not properly check user ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-1588

почти 14 лет назад

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-5233

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

CVSS2: 2.1
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-1636

Cross-site request forgery (CSRF) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of users for requests that delete stickynotes via unspecified vectors.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-1639

Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.

CVSS2: 3.5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-2153

Drupal 7.x before 7.14 does not properly restrict access to nodes in a list when using a "contributed node access module," which allows remote authenticated users with the "Access the content overview page" permission to read all published nodes by accessing the admin/content page.

CVSS2: 4
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-2153

Drupal 7.x before 7.14 does not properly restrict access to nodes in a ...

CVSS2: 4
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-1591

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows remote attackers to read private image styles.

CVSS2: 5
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-1591

The image module in Drupal 7.x before 7.14 does not properly check per ...

CVSS2: 5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-1590

The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

CVSS2: 4
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-1590

The forum list in Drupal 7.x before 7.14 does not properly check user ...

CVSS2: 4
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-1588

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVSS2: 3.5
1%
Низкий
почти 14 лет назад

Уязвимостей на страницу


Поделиться