Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Drupal

Drupalсистема управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.

Релизный цикл, информация об уязвимостях

Продукт: Drupal
Вендор: drupal

График релизов

11.310.611.42025202620272028

Недавние уязвимости Drupal

Количество 2 029

github логотип

GHSA-rpw6-9xfx-jvcx

больше 5 лет назад

Directory Traversal in Archive_Tar

CVSS3: 7.5
EPSS: Высокий
oracle-oval логотип

ELSA-2021-0860

больше 5 лет назад

ELSA-2021-0860: ipa security and bug fix update (MODERATE)

EPSS: Высокий
redhat логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2020-36193

больше 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
fstec логотип

BDU:2021-05279

больше 5 лет назад

Уязвимость файла Tar.php пакета Archive_Tar библиотеки классов PHP PEAR, связанная с некорректным ограничением имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2020-13671

больше 5 лет назад

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-13671

больше 5 лет назад

Drupal core does not properly sanitize certain filenames on uploaded f ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-13671

больше 5 лет назад

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-rpw6-9xfx-jvcx

Directory Traversal in Archive_Tar

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
oracle-oval логотип
ELSA-2021-0860

ELSA-2021-0860: ipa security and bug fix update (MODERATE)

84%
Высокий
больше 5 лет назад
redhat логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
nvd логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
debian логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
ubuntu логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
fstec логотип
BDU:2021-05279

Уязвимость файла Tar.php пакета Archive_Tar библиотеки классов PHP PEAR, связанная с некорректным ограничением имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 7.5
71%
Высокий
больше 5 лет назад
nvd логотип
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
4%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded f ...

CVSS3: 8.8
4%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-13671

Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.

CVSS3: 8.8
4%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться