Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.110.411.210.5202420252026

Недавние уязвимости Drupal

Количество 1 975

nvd логотип

CVE-2010-4521

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4521

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the Views module 6.x befor ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4520

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4520

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4519

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-4519

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-3686

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3686

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3685

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3685

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-4521

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4521

Cross-site scripting (XSS) vulnerability in the Views module 6.x befor ...

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4520

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4520

Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
почти 15 лет назад

Уязвимостей на страницу


Поделиться