Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

10.4202420252026

Недавние уязвимости Drupal

Количество 1 966

ubuntu логотип

CVE-2008-3740

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3743

почти 17 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2008-3661

почти 17 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Низкий
nvd логотип

CVE-2008-3222

почти 17 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2008-3221

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3220

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3219

почти 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3218

почти 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3223

почти 17 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-3222

почти 17 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2008-3740

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3743

Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.

CVSS2: 5.8
0%
Низкий
почти 17 лет назад
redhat логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVSS2: 5.8
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3221

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3220

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3219

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

CVSS2: 4.3
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3218

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.

CVSS2: 4.3
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVSS2: 5.8
1%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться