Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

github логотип

GHSA-qp8q-gwf5-hqh2

больше 4 лет назад

Drupal Cross-Site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ph8m-2h2f-qgr2

больше 4 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jq73-c7h9-wr72

больше 4 лет назад

Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

EPSS: Низкий
github логотип

GHSA-3gw2-26w5-pcm6

больше 4 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

EPSS: Низкий
github логотип

GHSA-vqp6-f6x9-5r96

больше 4 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

EPSS: Низкий
github логотип

GHSA-3v66-h3rq-pj5p

больше 4 лет назад

drupal6 version 6.16 has open redirection

EPSS: Низкий
fstec логотип

BDU:2022-02724

больше 4 лет назад

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-q7rv-6hp3-vh96

больше 4 лет назад

Improper Input Validation in guzzlehttp/psr7

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-24775

больше 4 лет назад

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-24775

больше 4 лет назад

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-qp8q-gwf5-hqh2

Drupal Cross-Site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-ph8m-2h2f-qgr2

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-jq73-c7h9-wr72

Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gw2-26w5-pcm6

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-vqp6-f6x9-5r96

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v66-h3rq-pj5p

drupal6 version 6.16 has open redirection

1%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-02724

Уязвимость ядра CMS-системы Drupal, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.4
больше 4 лет назад
github логотип
GHSA-q7rv-6hp3-vh96

Improper Input Validation in guzzlehttp/psr7

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-24775

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-24775

guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8 ...

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться