Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 012

Количество 2 012

github логотип

GHSA-gxxq-fhc7-3jv9

около 4 лет назад

Drupal Cross-Site Request Forgery (CSRF)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gx79-7p8q-959r

около 4 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

EPSS: Низкий
github логотип

GHSA-gvf2-2f4g-jqf4

больше 1 года назад

Drupal core contains a potential PHP Object Injection vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gjqg-9rhv-qj67

около 4 лет назад

Drupal Core Open Redirect vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-ghwc-95x2-682j

2 месяца назад

Drupal Core has a SQL Injection issue

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-gfh7-vc32-58w3

около 4 лет назад

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-g8mw-h5hw-6g35

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

EPSS: Низкий
github логотип

GHSA-g749-r93q-q2rq

около 4 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

EPSS: Низкий
github логотип

GHSA-g36h-4jr6-qmm9

больше 3 лет назад

Improper input validation in Drupal core

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fxww-mhrr-rf6r

около 4 лет назад

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

EPSS: Низкий
github логотип

GHSA-frqf-9qr4-6vxf

около 4 лет назад

Drupal Saving user accounts can sometimes grant the user all roles

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fmqh-2j2x-vgp3

около 4 лет назад

Drupal Unprivileged access to config export

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fmfv-x8mp-5767

больше 4 лет назад

Improper input validation in Drupal core

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fh8c-mghq-6w46

около 4 лет назад

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

EPSS: Низкий
github логотип

GHSA-fg5q-r2q5-qmh3

около 4 лет назад

Drupal CRLF injection vulnerability in the drupal_set_header function

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-ffxc-f678-c54f

около 4 лет назад

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

EPSS: Низкий
github логотип

GHSA-ff82-542x-8q28

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

EPSS: Низкий
github логотип

GHSA-fc7r-g457-hvgm

около 4 лет назад

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

EPSS: Низкий
github логотип

GHSA-f9cm-c972-9975

около 4 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

EPSS: Критический
github логотип

GHSA-f949-mcg2-v3qv

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gxxq-fhc7-3jv9

Drupal Cross-Site Request Forgery (CSRF)

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-gx79-7p8q-959r

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

3%
Низкий
около 4 лет назад
github логотип
GHSA-gvf2-2f4g-jqf4

Drupal core contains a potential PHP Object Injection vulnerability

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-gjqg-9rhv-qj67

Drupal Core Open Redirect vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-ghwc-95x2-682j

Drupal Core has a SQL Injection issue

CVSS3: 9.8
88%
Высокий
2 месяца назад
github логотип
GHSA-gfh7-vc32-58w3

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-g8mw-h5hw-6g35

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

1%
Низкий
около 4 лет назад
github логотип
GHSA-g749-r93q-q2rq

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

2%
Низкий
около 4 лет назад
github логотип
GHSA-g36h-4jr6-qmm9

Improper input validation in Drupal core

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-fxww-mhrr-rf6r

Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

2%
Низкий
около 4 лет назад
github логотип
GHSA-frqf-9qr4-6vxf

Drupal Saving user accounts can sometimes grant the user all roles

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-fmqh-2j2x-vgp3

Drupal Unprivileged access to config export

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-fmfv-x8mp-5767

Improper input validation in Drupal core

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-fh8c-mghq-6w46

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fg5q-r2q5-qmh3

Drupal CRLF injection vulnerability in the drupal_set_header function

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-ffxc-f678-c54f

CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

2%
Низкий
около 4 лет назад
github логотип
GHSA-ff82-542x-8q28

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.

2%
Низкий
около 4 лет назад
github логотип
GHSA-fc7r-g457-hvgm

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-f9cm-c972-9975

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

100%
Критический
около 4 лет назад
github логотип
GHSA-f949-mcg2-v3qv

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу