Количество 1 988
Количество 1 988
GHSA-g8mw-h5hw-6g35
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
GHSA-g749-r93q-q2rq
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
GHSA-g36h-4jr6-qmm9
Improper input validation in Drupal core
GHSA-fxww-mhrr-rf6r
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
GHSA-frqf-9qr4-6vxf
Drupal Saving user accounts can sometimes grant the user all roles
GHSA-fmqh-2j2x-vgp3
Drupal Unprivileged access to config export
GHSA-fmfv-x8mp-5767
Improper input validation in Drupal core
GHSA-fh8c-mghq-6w46
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
GHSA-fg5q-r2q5-qmh3
Drupal CRLF injection vulnerability in the drupal_set_header function
GHSA-ffxc-f678-c54f
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
GHSA-ff82-542x-8q28
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.
GHSA-fc7r-g457-hvgm
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
GHSA-f9cm-c972-9975
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
GHSA-f949-mcg2-v3qv
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
GHSA-f8mj-2m92-pmqv
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
GHSA-f7pq-g2g4-v3h6
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.
GHSA-f4qx-jqfq-7785
Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions
GHSA-f46h-72fj-m37w
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
GHSA-cv5p-xvxc-9fqp
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
GHSA-cv5g-6h34-8w32
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-g8mw-h5hw-6g35 Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | 0% Низкий | больше 3 лет назад | ||
GHSA-g749-r93q-q2rq The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name. | 0% Низкий | больше 3 лет назад | ||
GHSA-g36h-4jr6-qmm9 Improper input validation in Drupal core | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-fxww-mhrr-rf6r Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. | 1% Низкий | больше 3 лет назад | ||
GHSA-frqf-9qr4-6vxf Drupal Saving user accounts can sometimes grant the user all roles | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-fmqh-2j2x-vgp3 Drupal Unprivileged access to config export | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-fmfv-x8mp-5767 Improper input validation in Drupal core | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-fh8c-mghq-6w46 The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. | 0% Низкий | больше 3 лет назад | ||
GHSA-fg5q-r2q5-qmh3 Drupal CRLF injection vulnerability in the drupal_set_header function | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-ffxc-f678-c54f CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy. | 1% Низкий | больше 3 лет назад | ||
GHSA-ff82-542x-8q28 Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7. | 1% Низкий | больше 3 лет назад | ||
GHSA-fc7r-g457-hvgm The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors. | 2% Низкий | больше 3 лет назад | ||
GHSA-f9cm-c972-9975 The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | 94% Критический | больше 3 лет назад | ||
GHSA-f949-mcg2-v3qv Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names. | 0% Низкий | больше 3 лет назад | ||
GHSA-f8mj-2m92-pmqv Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack. | 0% Низкий | больше 3 лет назад | ||
GHSA-f7pq-g2g4-v3h6 Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files. | 1% Низкий | больше 3 лет назад | ||
GHSA-f4qx-jqfq-7785 Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-f46h-72fj-m37w The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-cv5p-xvxc-9fqp Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form. | 0% Низкий | больше 3 лет назад | ||
GHSA-cv5g-6h34-8w32 The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу