Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.110.411.210.5202420252026

Недавние уязвимости Drupal

Количество 1 975

github логотип

GHSA-r44v-cp4f-j8gv

больше 3 лет назад

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

EPSS: Низкий
github логотип

GHSA-wmq2-h8g3-fgwr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.

EPSS: Низкий
github логотип

GHSA-62j6-xwg5-q36g

больше 3 лет назад

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-5wch-vc4h-wx4j

больше 3 лет назад

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).

EPSS: Низкий
github логотип

GHSA-hw7f-w767-vqpp

больше 3 лет назад

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

EPSS: Низкий
github логотип

GHSA-j47j-5wh7-4gmm

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

EPSS: Низкий
github логотип

GHSA-c33g-h7g2-frf6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

EPSS: Низкий
github логотип

GHSA-fh8c-mghq-6w46

больше 3 лет назад

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

EPSS: Низкий
github логотип

GHSA-7q56-gvfr-6f9w

больше 3 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

EPSS: Низкий
github логотип

GHSA-96vx-qf28-6f8m

больше 3 лет назад

Drupal Access Control Bypass

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-r44v-cp4f-j8gv

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wmq2-h8g3-fgwr

Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-62j6-xwg5-q36g

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-5wch-vc4h-wx4j

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hw7f-w767-vqpp

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-j47j-5wh7-4gmm

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c33g-h7g2-frf6

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fh8c-mghq-6w46

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-7q56-gvfr-6f9w

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-96vx-qf28-6f8m

Drupal Access Control Bypass

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться