Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 012

nvd логотип

CVE-2005-3974

больше 20 лет назад

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-3973

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2005-3973

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 th ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2005-3975

больше 20 лет назад

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and ...

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2005-3974

больше 20 лет назад

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PH ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-3974

больше 20 лет назад

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-3973

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3975

больше 20 лет назад

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2005-2106

около 21 года назад

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1921

около 21 года назад

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

CVSS2: 7.5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2005-3974

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

CVSS2: 6.4
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3973

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-3973

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 th ...

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-3975

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and ...

CVSS2: 4
5%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-3974

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PH ...

CVSS2: 6.4
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3974

Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers to bypass the "access user profiles" permission.

CVSS2: 6.4
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3973

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3975

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.

CVSS2: 4
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2106

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1921

Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.

CVSS2: 7.5
79%
Высокий
около 21 года назад

Уязвимостей на страницу


Поделиться