Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 012

nvd логотип

CVE-2006-4002

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-4002

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-4002

почти 20 лет назад

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-3570

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-3570

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the webform module in Drup ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-3570

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-2831

около 20 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-2833

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-2832

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-2832

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the upload module (upload. ...

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-4002

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
debian логотип
CVE-2006-4002

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 ...

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2006-4002

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

CVSS2: 4.3
1%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-3570

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
около 20 лет назад
debian логотип
CVE-2006-3570

Cross-site scripting (XSS) vulnerability in the webform module in Drup ...

CVSS2: 4.3
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-3570

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-2831

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

CVSS2: 7.5
4%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-2833

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

CVSS2: 2.6
3%
Низкий
около 20 лет назад
nvd логотип
CVE-2006-2832

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

CVSS2: 2.6
1%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2832

Cross-site scripting (XSS) vulnerability in the upload module (upload. ...

CVSS2: 2.6
1%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться