Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 029

Количество 2 029

github логотип

GHSA-fjjr-558r-wpvr

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in revisioning_theme.inc in the Taxonomy module in the Revisioning module 6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) tags or (2) term parameters.

EPSS: Низкий
github логотип

GHSA-fhj7-xvhv-gcv6

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-fggw-vrpv-jh99

больше 4 лет назад

The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node privileges in certain circumstances involving subqueue creation, which allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.

EPSS: Низкий
github логотип

GHSA-ff2g-3pvh-5fjr

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-f9j7-vff8-3c2r

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.

EPSS: Низкий
github логотип

GHSA-f7q5-4r7c-4f6x

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.

EPSS: Низкий
github логотип

GHSA-f5rv-ph9h-95jp

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to the "$conf variable in settings.php."

EPSS: Низкий
github логотип

GHSA-f5r3-jgh2-p373

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."

EPSS: Низкий
github логотип

GHSA-f5r2-9xf3-m4j7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

EPSS: Низкий
github логотип

GHSA-f5cf-wmjx-wx2h

больше 4 лет назад

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

EPSS: Низкий
github логотип

GHSA-f3qm-qhc2-594f

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-f2wf-25xc-69c9

около 4 лет назад

Failure to strip the Cookie header on change in host or HTTP downgrade

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cxmw-fgm7-87f2

больше 4 лет назад

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS: Низкий
github логотип

GHSA-cwqc-w7f5-59qr

больше 4 лет назад

Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-cwq8-5gf7-6jfp

около 4 лет назад

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

EPSS: Низкий
github логотип

GHSA-cwmx-hcrq-mhc3

около 4 лет назад

Cross-domain cookie leakage in Guzzle

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-cwh7-7597-4728

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

EPSS: Низкий
github логотип

GHSA-cw26-3hx5-52c9

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

EPSS: Низкий
github логотип

GHSA-cr4r-2wf7-9633

около 4 лет назад

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

EPSS: Низкий
github логотип

GHSA-cqmc-38m3-4v5v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fjjr-558r-wpvr

Multiple cross-site scripting (XSS) vulnerabilities in revisioning_theme.inc in the Taxonomy module in the Revisioning module 6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) tags or (2) term parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fhj7-xvhv-gcv6

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-fggw-vrpv-jh99

The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node privileges in certain circumstances involving subqueue creation, which allows remote authenticated users to discover arbitrary organic group names by reading confirmation messages.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-ff2g-3pvh-5fjr

Cross-site scripting (XSS) vulnerability in the Submenu Tree module before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-f9j7-vff8-3c2r

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-f7q5-4r7c-4f6x

Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-f5rv-ph9h-95jp

Cross-site scripting (XSS) vulnerability in the Advertisement module 6.x-2.x before 6.x-2.3 for Drupal, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to the "$conf variable in settings.php."

2%
Низкий
около 4 лет назад
github логотип
GHSA-f5r3-jgh2-p373

Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files."

1%
Низкий
около 4 лет назад
github логотип
GHSA-f5r2-9xf3-m4j7

Cross-site scripting (XSS) vulnerability in the stickynote module before 7.x-1.1 for Drupal allows remote authenticated users with edit stickynotes privileges to inject arbitrary web script or HTML via unspecified vecotrs.

2%
Низкий
около 4 лет назад
github логотип
GHSA-f5cf-wmjx-wx2h

The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-f3qm-qhc2-594f

Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-f2wf-25xc-69c9

Failure to strip the Cookie header on change in host or HTTP downgrade

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-cxmw-fgm7-87f2

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-cwqc-w7f5-59qr

Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-cwq8-5gf7-6jfp

The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cwmx-hcrq-mhc3

Cross-domain cookie leakage in Guzzle

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-cwh7-7597-4728

Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-cw26-3hx5-52c9

Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.

1%
Низкий
около 4 лет назад
github логотип
GHSA-cr4r-2wf7-9633

The Fivestar module 6.x-1.x before 6.x-1.20 for Drupal does not properly validate voting data, which allows remote attackers to manipulate voting averages via a negative value in the vote parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-cqmc-38m3-4v5v

Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied information."

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу