Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

debian логотип

CVE-2008-3223

больше 17 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-3222

больше 17 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2008-3218

больше 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3220

больше 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5 ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3219

больше 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3221

больше 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3218

больше 17 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3219

больше 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3220

больше 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3223

больше 17 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 ...

CVSS2: 7.5
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVSS2: 5.8
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3218

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3220

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5 ...

CVSS2: 4.3
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3219

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before ...

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3221

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6 ...

CVSS2: 4.3
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-3218

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-3219

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-3220

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
1%
Низкий
больше 17 лет назад

Уязвимостей на страницу


Поделиться