Количество 2 012
Количество 2 012
GHSA-f8mj-2m92-pmqv
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
GHSA-f7pq-g2g4-v3h6
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.
GHSA-f4qx-jqfq-7785
Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions
GHSA-f46h-72fj-m37w
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors.
GHSA-f3cj-mjqm-fhvj
Drupal core is Vulnerable to Cross-Site Scripting
GHSA-cv5p-xvxc-9fqp
Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
GHSA-cv5g-6h34-8w32
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
GHSA-cmmh-8mwp-gq5p
Drupal Cross Site Scripting (XSS) vulnerability
GHSA-ch7c-r59p-c6q5
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.
GHSA-cfh2-7f6h-3m85
Access bypass in Drupal Core
GHSA-c9jq-ww5c-g3v9
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
GHSA-c6j8-r888-r854
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.
GHSA-c533-c843-67h8
Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor
GHSA-c33g-h7g2-frf6
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
GHSA-9x6f-gcx8-396p
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.
GHSA-9wh5-5mcm-hf2j
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
GHSA-9p8g-gj5w-ghcm
Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information.
GHSA-9f2c-79x6-jgvf
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
GHSA-9c24-g32g-35rj
Drupal PECL YAML parser unsafe object handling
GHSA-98w5-wqp9-w466
Drupal Incorrect cache context on password reset page
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-f8mj-2m92-pmqv Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack. | 1% Низкий | около 4 лет назад | ||
GHSA-f7pq-g2g4-v3h6 Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files. | 2% Низкий | около 4 лет назад | ||
GHSA-f4qx-jqfq-7785 Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-f46h-72fj-m37w The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendly version" permission to read node titles and possibly node content via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-f3cj-mjqm-fhvj Drupal core is Vulnerable to Cross-Site Scripting | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
GHSA-cv5p-xvxc-9fqp Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form. | 1% Низкий | около 4 лет назад | ||
GHSA-cv5g-6h34-8w32 The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name. | 2% Низкий | около 4 лет назад | ||
GHSA-cmmh-8mwp-gq5p Drupal Cross Site Scripting (XSS) vulnerability | CVSS3: 5.4 | 12% Средний | около 4 лет назад | |
GHSA-ch7c-r59p-c6q5 Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. | 1% Низкий | около 4 лет назад | ||
GHSA-cfh2-7f6h-3m85 Access bypass in Drupal Core | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-c9jq-ww5c-g3v9 SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc. | 1% Низкий | около 4 лет назад | ||
GHSA-c6j8-r888-r854 The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page. | 1% Низкий | около 4 лет назад | ||
GHSA-c533-c843-67h8 Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-c33g-h7g2-frf6 Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label. | 1% Низкий | около 4 лет назад | ||
GHSA-9x6f-gcx8-396p The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue. | 1% Низкий | около 4 лет назад | ||
GHSA-9wh5-5mcm-hf2j Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. | CVSS3: 5.4 | 0% Низкий | 20 дней назад | |
GHSA-9p8g-gj5w-ghcm Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information. | 2% Низкий | около 4 лет назад | ||
GHSA-9f2c-79x6-jgvf Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack. | 2% Низкий | около 4 лет назад | ||
GHSA-9c24-g32g-35rj Drupal PECL YAML parser unsafe object handling | CVSS3: 9.8 | 20% Средний | около 4 лет назад | |
GHSA-98w5-wqp9-w466 Drupal Incorrect cache context on password reset page | CVSS3: 7.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу