Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

redhat логотип

CVE-2009-1575

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

EPSS: Низкий
nvd логотип

CVE-2009-1344

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in the Localization client module 5.x before 5.x-1.2 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the translation functionality.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1343

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before 6.x-1.5, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via content titles.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1342

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-1249

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-6533

почти 17 лет назад

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-6533

почти 17 лет назад

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-6532

почти 17 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2008-6532

почти 17 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the upda ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6532

почти 17 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2009-1575

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-1344

Cross-site scripting (XSS) vulnerability in the Localization client module 5.x before 5.x-1.2 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the translation functionality.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-1343

Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.5 and 6.x before 6.x-1.5, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via content titles.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-1342

Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-1249

Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-6533

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-6533

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related ...

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-6532

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

CVSS2: 6.8
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-6532

Multiple cross-site request forgery (CSRF) vulnerabilities in the upda ...

CVSS2: 6.8
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6532

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

CVSS2: 6.8
0%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться