Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

github логотип

GHSA-ff2g-3pvh-5fjr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-f9j7-vff8-3c2r

почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.

EPSS: Низкий
github логотип

GHSA-f7q5-4r7c-4f6x

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.

EPSS: Низкий
github логотип

GHSA-f5rv-ph9h-95jp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to the "$conf variable in settings.php."

EPSS: Низкий
github логотип

GHSA-f5r3-jgh2-p373

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."

EPSS: Низкий
github логотип

GHSA-f5r2-9xf3-m4j7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

EPSS: Низкий
github логотип

GHSA-f5cf-wmjx-wx2h

почти 4 года назад

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

EPSS: Низкий
github логотип

GHSA-f3qm-qhc2-594f

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-f2wf-25xc-69c9

больше 3 лет назад

Failure to strip the Cookie header on change in host or HTTP downgrade

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cxmw-fgm7-87f2

почти 4 года назад

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS: Низкий
github логотип

GHSA-cwqc-w7f5-59qr

почти 4 года назад

Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-cwq8-5gf7-6jfp

больше 3 лет назад

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

EPSS: Низкий
github логотип

GHSA-cwmx-hcrq-mhc3

больше 3 лет назад

Cross-domain cookie leakage in Guzzle

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-cwh7-7597-4728

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

EPSS: Низкий
github логотип

GHSA-cw26-3hx5-52c9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

EPSS: Низкий
github логотип

GHSA-cr4r-2wf7-9633

больше 3 лет назад

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

EPSS: Низкий
github логотип

GHSA-cqmc-38m3-4v5v

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."

EPSS: Низкий
github логотип

GHSA-cq98-4r72-wm2g

больше 3 лет назад

Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

EPSS: Низкий
github логотип

GHSA-cq3q-q7wq-586q

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.

EPSS: Низкий
github логотип

GHSA-chr9-m3cf-vvxr

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-ff2g-3pvh-5fjr

Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f9j7-vff8-3c2r

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.

0%
Низкий
почти 4 года назад
github логотип
GHSA-f7q5-4r7c-4f6x

Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.

0%
Низкий
почти 4 года назад
github логотип
GHSA-f5rv-ph9h-95jp

Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to the "$conf variable in settings.php."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f5r3-jgh2-p373

Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f5r2-9xf3-m4j7

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f5cf-wmjx-wx2h

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

1%
Низкий
почти 4 года назад
github логотип
GHSA-f3qm-qhc2-594f

Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f2wf-25xc-69c9

Failure to strip the Cookie header on change in host or HTTP downgrade

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cxmw-fgm7-87f2

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

1%
Низкий
почти 4 года назад
github логотип
GHSA-cwqc-w7f5-59qr

Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-cwq8-5gf7-6jfp

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cwmx-hcrq-mhc3

Cross-domain cookie leakage in Guzzle

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cwh7-7597-4728

Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

0%
Низкий
почти 4 года назад
github логотип
GHSA-cw26-3hx5-52c9

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cr4r-2wf7-9633

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cqmc-38m3-4v5v

Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."

0%
Низкий
почти 4 года назад
github логотип
GHSA-cq98-4r72-wm2g

Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-cq3q-q7wq-586q

Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.

0%
Низкий
почти 4 года назад
github логотип
GHSA-chr9-m3cf-vvxr

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу