Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

github логотип

GHSA-cxmw-fgm7-87f2

больше 3 лет назад

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS: Низкий
github логотип

GHSA-cwqc-w7f5-59qr

больше 3 лет назад

Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-cwq8-5gf7-6jfp

больше 3 лет назад

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

EPSS: Низкий
github логотип

GHSA-cwmx-hcrq-mhc3

около 3 лет назад

Cross-domain cookie leakage in Guzzle

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-cwh7-7597-4728

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

EPSS: Низкий
github логотип

GHSA-cw26-3hx5-52c9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

EPSS: Низкий
github логотип

GHSA-cr4r-2wf7-9633

больше 3 лет назад

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

EPSS: Низкий
github логотип

GHSA-cqmc-38m3-4v5v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."

EPSS: Низкий
github логотип

GHSA-cq98-4r72-wm2g

больше 3 лет назад

Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

EPSS: Низкий
github логотип

GHSA-cq3q-q7wq-586q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.

EPSS: Низкий
github логотип

GHSA-chr9-m3cf-vvxr

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

EPSS: Низкий
github логотип

GHSA-chjx-2g2v-7rvr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.

EPSS: Низкий
github логотип

GHSA-ch2p-q2rq-mx89

больше 3 лет назад

Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-cggr-42mf-4mqj

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.

EPSS: Низкий
github логотип

GHSA-cg8w-5vgp-3c2r

больше 3 лет назад

The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles.

EPSS: Низкий
github логотип

GHSA-cg66-88cp-whx8

больше 3 лет назад

Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot directories via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-cg2x-449f-pwgw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.

EPSS: Низкий
github логотип

GHSA-cfc7-w9hw-779w

больше 3 лет назад

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

EPSS: Высокий
github логотип

GHSA-cchx-mfrc-fwqr

больше 5 лет назад

Improper authentication in Symfony

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c9fr-6667-m4vh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cxmw-fgm7-87f2

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cwqc-w7f5-59qr

Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cwq8-5gf7-6jfp

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cwmx-hcrq-mhc3

Cross-domain cookie leakage in Guzzle

CVSS3: 8
0%
Низкий
около 3 лет назад
github логотип
GHSA-cwh7-7597-4728

Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cw26-3hx5-52c9

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cr4r-2wf7-9633

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cqmc-38m3-4v5v

Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cq98-4r72-wm2g

Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cq3q-q7wq-586q

Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-chr9-m3cf-vvxr

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-chjx-2g2v-7rvr

Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-ch2p-q2rq-mx89

Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cggr-42mf-4mqj

Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cg8w-5vgp-3c2r

The node selection interface in the WYSIWYG editor (CKEditor) in the Node Embed module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.0 for Drupal does not properly check permissions, which allows remote attackers to bypass intended access restrictions and read node titles.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cg66-88cp-whx8

Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot directories via unknown attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cg2x-449f-pwgw

Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cfc7-w9hw-779w

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

77%
Высокий
больше 3 лет назад
github логотип
GHSA-cchx-mfrc-fwqr

Improper authentication in Symfony

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-c9fr-6667-m4vh

Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу