Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 975

CVE-2010-4521
Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.
CVE-2010-4521
Cross-site scripting (XSS) vulnerability in the Views module 6.x befor ...

CVE-2010-4520
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.
CVE-2010-4520
Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVE-2010-4519
Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.
CVE-2010-4519
Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVE-2010-3686
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CVE-2010-3686
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVE-2010-3685
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CVE-2010-3685
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2010-4521 Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path. | CVSS2: 4.3 | 0% Низкий | больше 14 лет назад |
CVE-2010-4521 Cross-site scripting (XSS) vulnerability in the Views module 6.x befor ... | CVSS2: 4.3 | 0% Низкий | больше 14 лет назад | |
![]() | CVE-2010-4520 Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title. | CVSS2: 4.3 | 0% Низкий | больше 14 лет назад |
CVE-2010-4520 Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ... | CVSS2: 4.3 | 0% Низкий | больше 14 лет назад | |
![]() | CVE-2010-4519 Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views. | CVSS2: 6.8 | 0% Низкий | больше 14 лет назад |
CVE-2010-4519 Multiple cross-site request forgery (CSRF) vulnerabilities in the View ... | CVSS2: 6.8 | 0% Низкий | больше 14 лет назад | |
![]() | CVE-2010-3686 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider. | CVSS2: 5 | 1% Низкий | почти 15 лет назад |
CVE-2010-3686 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ... | CVSS2: 5 | 1% Низкий | почти 15 лет назад | |
![]() | CVE-2010-3685 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider. | CVSS2: 5 | 1% Низкий | почти 15 лет назад |
CVE-2010-3685 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ... | CVSS2: 5 | 1% Низкий | почти 15 лет назад |
Уязвимостей на страницу