Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"
Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.210.511.310.6202520262027

Недавние уязвимости Drupal

Количество 1 988

nvd логотип

CVE-2020-13671

около 5 лет назад

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-13671

около 5 лет назад

Drupal core does not properly sanitize certain filenames on uploaded f ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-13671

около 5 лет назад

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
EPSS: Критический
debian логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to addre ...

CVSS3: 7.8
EPSS: Критический
nvd логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Высокий
debian логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because ph ...

CVSS3: 7.8
EPSS: Высокий
ubuntu логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
EPSS: Критический
ubuntu логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Высокий
redhat логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
5%
Низкий
около 5 лет назад
debian логотип
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded f ...

CVSS3: 8.8
5%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
5%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
93%
Критический
около 5 лет назад
debian логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to addre ...

CVSS3: 7.8
93%
Критический
около 5 лет назад
nvd логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
76%
Высокий
около 5 лет назад
debian логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because ph ...

CVSS3: 7.8
76%
Высокий
около 5 лет назад
ubuntu логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
93%
Критический
около 5 лет назад
ubuntu логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
76%
Высокий
около 5 лет назад
redhat логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
76%
Высокий
около 5 лет назад

Уязвимостей на страницу


Поделиться