Количество 2 012
Количество 2 012
GHSA-gxxq-fhc7-3jv9
Drupal Cross-Site Request Forgery (CSRF)
GHSA-gx79-7p8q-959r
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
GHSA-gvf2-2f4g-jqf4
Drupal core contains a potential PHP Object Injection vulnerability
GHSA-gjqg-9rhv-qj67
Drupal Core Open Redirect vulnerability
GHSA-ghwc-95x2-682j
Drupal Core has a SQL Injection issue
GHSA-gfh7-vc32-58w3
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
GHSA-g8mw-h5hw-6g35
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
GHSA-g749-r93q-q2rq
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
GHSA-g36h-4jr6-qmm9
Improper input validation in Drupal core
GHSA-fxww-mhrr-rf6r
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
GHSA-frqf-9qr4-6vxf
Drupal Saving user accounts can sometimes grant the user all roles
GHSA-fmqh-2j2x-vgp3
Drupal Unprivileged access to config export
GHSA-fmfv-x8mp-5767
Improper input validation in Drupal core
GHSA-fh8c-mghq-6w46
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
GHSA-fg5q-r2q5-qmh3
Drupal CRLF injection vulnerability in the drupal_set_header function
GHSA-ffxc-f678-c54f
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.
GHSA-ff82-542x-8q28
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7.
GHSA-fc7r-g457-hvgm
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
GHSA-f9cm-c972-9975
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
GHSA-f949-mcg2-v3qv
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-gxxq-fhc7-3jv9 Drupal Cross-Site Request Forgery (CSRF) | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-gx79-7p8q-959r SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields." | 3% Низкий | около 4 лет назад | ||
GHSA-gvf2-2f4g-jqf4 Drupal core contains a potential PHP Object Injection vulnerability | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-gjqg-9rhv-qj67 Drupal Core Open Redirect vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-ghwc-95x2-682j Drupal Core has a SQL Injection issue | CVSS3: 9.8 | 88% Высокий | 2 месяца назад | |
GHSA-gfh7-vc32-58w3 CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-g8mw-h5hw-6g35 Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | 1% Низкий | около 4 лет назад | ||
GHSA-g749-r93q-q2rq The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name. | 2% Низкий | около 4 лет назад | ||
GHSA-g36h-4jr6-qmm9 Improper input validation in Drupal core | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-fxww-mhrr-rf6r Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. | 2% Низкий | около 4 лет назад | ||
GHSA-frqf-9qr4-6vxf Drupal Saving user accounts can sometimes grant the user all roles | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-fmqh-2j2x-vgp3 Drupal Unprivileged access to config export | CVSS3: 4.3 | 2% Низкий | около 4 лет назад | |
GHSA-fmfv-x8mp-5767 Improper input validation in Drupal core | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-fh8c-mghq-6w46 The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. | 1% Низкий | около 4 лет назад | ||
GHSA-fg5q-r2q5-qmh3 Drupal CRLF injection vulnerability in the drupal_set_header function | CVSS3: 5.9 | 1% Низкий | около 4 лет назад | |
GHSA-ffxc-f678-c54f CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy. | 2% Низкий | около 4 лет назад | ||
GHSA-ff82-542x-8q28 Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7. | 2% Низкий | около 4 лет назад | ||
GHSA-fc7r-g457-hvgm The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors. | 3% Низкий | около 4 лет назад | ||
GHSA-f9cm-c972-9975 The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | 100% Критический | около 4 лет назад | ||
GHSA-f949-mcg2-v3qv Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated administrators to inject arbitrary web script or HTML via custom content type names. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу