Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-fxww-mhrr-rf6r

около 3 лет назад

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

EPSS: Низкий
github логотип

GHSA-frqf-9qr4-6vxf

около 3 лет назад

Drupal Saving user accounts can sometimes grant the user all roles

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fmqh-2j2x-vgp3

около 3 лет назад

Drupal Unprivileged access to config export

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fmfv-x8mp-5767

больше 3 лет назад

Improper input validation in Drupal core

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fh8c-mghq-6w46

около 3 лет назад

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

EPSS: Низкий
github логотип

GHSA-fg5q-r2q5-qmh3

около 3 лет назад

Drupal CRLF injection vulnerability in the drupal_set_header function

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-ffxc-f678-c54f

около 3 лет назад

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

EPSS: Низкий
github логотип

GHSA-ff82-542x-8q28

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

EPSS: Низкий
github логотип

GHSA-fc7r-g457-hvgm

около 3 лет назад

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

EPSS: Низкий
github логотип

GHSA-f9cm-c972-9975

около 3 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

EPSS: Критический
github логотип

GHSA-f949-mcg2-v3qv

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

EPSS: Низкий
github логотип

GHSA-f8mj-2m92-pmqv

около 3 лет назад

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

EPSS: Низкий
github логотип

GHSA-f7pq-g2g4-v3h6

около 3 лет назад

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

EPSS: Низкий
github логотип

GHSA-f4qx-jqfq-7785

около 3 лет назад

Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-f46h-72fj-m37w

около 3 лет назад

The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-cv5p-xvxc-9fqp

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

EPSS: Низкий
github логотип

GHSA-cv5g-6h34-8w32

около 3 лет назад

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

EPSS: Низкий
github логотип

GHSA-cmmh-8mwp-gq5p

около 3 лет назад

Drupal Cross Site Scripting (XSS) vulnerability

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-ch7c-r59p-c6q5

около 3 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

EPSS: Низкий
github логотип

GHSA-cfh2-7f6h-3m85

около 2 лет назад

Access bypass in Drupal Core

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fxww-mhrr-rf6r

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

1%
Низкий
около 3 лет назад
github логотип
GHSA-frqf-9qr4-6vxf

Drupal Saving user accounts can sometimes grant the user all roles

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-fmqh-2j2x-vgp3

Drupal Unprivileged access to config export

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-fmfv-x8mp-5767

Improper input validation in Drupal core

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fh8c-mghq-6w46

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

0%
Низкий
около 3 лет назад
github логотип
GHSA-fg5q-r2q5-qmh3

Drupal CRLF injection vulnerability in the drupal_set_header function

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-ffxc-f678-c54f

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

1%
Низкий
около 3 лет назад
github логотип
GHSA-ff82-542x-8q28

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

1%
Низкий
около 3 лет назад
github логотип
GHSA-fc7r-g457-hvgm

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

5%
Низкий
около 3 лет назад
github логотип
GHSA-f9cm-c972-9975

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

94%
Критический
около 3 лет назад
github логотип
GHSA-f949-mcg2-v3qv

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

0%
Низкий
около 3 лет назад
github логотип
GHSA-f8mj-2m92-pmqv

Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.

0%
Низкий
около 3 лет назад
github логотип
GHSA-f7pq-g2g4-v3h6

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

1%
Низкий
около 3 лет назад
github логотип
GHSA-f4qx-jqfq-7785

Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-f46h-72fj-m37w

The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cv5p-xvxc-9fqp

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cv5g-6h34-8w32

The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

1%
Низкий
около 3 лет назад
github логотип
GHSA-cmmh-8mwp-gq5p

Drupal Cross Site Scripting (XSS) vulnerability

CVSS3: 5.4
58%
Средний
около 3 лет назад
github логотип
GHSA-ch7c-r59p-c6q5

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cfh2-7f6h-3m85

Access bypass in Drupal Core

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу