Количество 2 029
Количество 2 029
GHSA-gxxq-fhc7-3jv9
Drupal Cross-Site Request Forgery (CSRF)
GHSA-gx79-7p8q-959r
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
GHSA-gvf2-2f4g-jqf4
Drupal core contains a potential PHP Object Injection vulnerability
GHSA-gjqg-9rhv-qj67
Drupal Core Open Redirect vulnerability
GHSA-ghwc-95x2-682j
Drupal Core has a SQL Injection issue
GHSA-gfh7-vc32-58w3
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
GHSA-g8mw-h5hw-6g35
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
GHSA-g749-r93q-q2rq
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
GHSA-g36h-4jr6-qmm9
Improper input validation in Drupal core
GHSA-fxww-mhrr-rf6r
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
GHSA-frqf-9qr4-6vxf
Drupal Saving user accounts can sometimes grant the user all roles
GHSA-fmqh-2j2x-vgp3
Drupal Unprivileged access to config export
GHSA-fmfv-x8mp-5767
Improper input validation in Drupal core
GHSA-fh8c-mghq-6w46
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
GHSA-fg5q-r2q5-qmh3
Drupal CRLF injection vulnerability in the drupal_set_header function
GHSA-ffxc-f678-c54f
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
GHSA-ff82-542x-8q28
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.
GHSA-fc7r-g457-hvgm
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
GHSA-f9cm-c972-9975
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
GHSA-f949-mcg2-v3qv
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-gxxq-fhc7-3jv9 Drupal Cross-Site Request Forgery (CSRF) | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-gx79-7p8q-959r SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields." | 3% Низкий | больше 4 лет назад | ||
GHSA-gvf2-2f4g-jqf4 Drupal core contains a potential PHP Object Injection vulnerability | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
GHSA-gjqg-9rhv-qj67 Drupal Core Open Redirect vulnerability | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-ghwc-95x2-682j Drupal Core has a SQL Injection issue | CVSS3: 9.8 | 88% Высокий | 4 месяца назад | |
GHSA-gfh7-vc32-58w3 CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-g8mw-h5hw-6g35 Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | 1% Низкий | больше 4 лет назад | ||
GHSA-g749-r93q-q2rq The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name. | 2% Низкий | больше 4 лет назад | ||
GHSA-g36h-4jr6-qmm9 Improper input validation in Drupal core | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-fxww-mhrr-rf6r Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. | 2% Низкий | больше 4 лет назад | ||
GHSA-frqf-9qr4-6vxf Drupal Saving user accounts can sometimes grant the user all roles | CVSS3: 8.8 | 3% Низкий | больше 4 лет назад | |
GHSA-fmqh-2j2x-vgp3 Drupal Unprivileged access to config export | CVSS3: 4.3 | 2% Низкий | больше 4 лет назад | |
GHSA-fmfv-x8mp-5767 Improper input validation in Drupal core | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-fh8c-mghq-6w46 The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. | 1% Низкий | больше 4 лет назад | ||
GHSA-fg5q-r2q5-qmh3 Drupal CRLF injection vulnerability in the drupal_set_header function | CVSS3: 5.9 | 1% Низкий | больше 4 лет назад | |
GHSA-ffxc-f678-c54f CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy. | 2% Низкий | больше 4 лет назад | ||
GHSA-ff82-542x-8q28 Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7. | 2% Низкий | больше 4 лет назад | ||
GHSA-fc7r-g457-hvgm The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-f9cm-c972-9975 The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | 100% Критический | больше 4 лет назад | ||
GHSA-f949-mcg2-v3qv Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу