Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.110.411.210.5202420252026

Недавние уязвимости Drupal

Количество 1 975

nvd логотип

CVE-2008-7151

почти 16 лет назад

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-7150

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in Refine by Taxonomy 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a taxonomy term, which is not properly handled by refine_by_taxo when displaying tags.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-6972

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2008-6910

около 16 лет назад

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-6909

около 16 лет назад

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2008-6908

около 16 лет назад

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-2610

около 16 лет назад

Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-2572

около 16 лет назад

Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-2374

около 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2374

около 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-7151

Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to hijack the authentication of unspecified privileged users for requests that can be leveraged to execute arbitrary PHP code.

CVSS2: 6.8
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2008-7150

Cross-site scripting (XSS) vulnerability in Refine by Taxonomy 5.x before 5.x-0.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a taxonomy term, which is not properly handled by refine_by_taxo when displaying tags.

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2008-6972

Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.

CVSS2: 3.5
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2008-6910

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2008-6909

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.

CVSS2: 6.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2008-6908

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-2610

Cross-site scripting (XSS) vulnerability in the Links Related module in the Links Package 5.x before 5.x-1.13 and 6.x before 6.x-1.2, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via the title field.

CVSS2: 3.5
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-2572

Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.

CVSS2: 6.8
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
0%
Низкий
около 16 лет назад
debian логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ...

CVSS2: 4.3
0%
Низкий
около 16 лет назад

Уязвимостей на страницу


Поделиться