Drupal — система управления контентом с открытым исходным кодом. На Drupal работает более миллиона сайтов — от личных блогов до сайтов компаний, политических партий и государственных организаций.
Релизный цикл, информация об уязвимостях
График релизов
Количество 2 029
CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...
CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x before 6 ...
CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
CVE-2010-2250
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
CVE-2010-2250
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...
CVE-2010-2250
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
CVE-2010-2471
Drupal versions 5.x and 6.x has open redirection
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2010-2473 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2473 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ... | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2472 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | CVSS3: 4.8 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2472 Locale module and dependent contributed modules in Drupal 6.x before 6 ... | CVSS3: 4.8 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2472 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | CVSS3: 4.8 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2473 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | CVSS3: 6.5 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2250 Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2250 Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ... | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2250 Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2010-2471 Drupal versions 5.x and 6.x has open redirection | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу