Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

ubuntu логотип

CVE-2006-2260

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1227

больше 20 лет назад

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2006-1228

больше 20 лет назад

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-1226

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-1225

больше 20 лет назад

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-1227

больше 20 лет назад

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is ...

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2006-1226

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-1225

больше 20 лет назад

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x be ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-1228

больше 20 лет назад

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1226

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2006-2260

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1227

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.

CVSS2: 4.6
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

CVSS2: 5.1
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1226

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-1225

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

CVSS2: 5
2%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1227

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is ...

CVSS2: 4.6
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1226

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 ...

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1225

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x be ...

CVSS2: 5
2%
Низкий
больше 20 лет назад
debian логотип
CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x ...

CVSS2: 5.1
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1226

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад

Уязвимостей на страницу


Поделиться