Количество 1 988
Количество 1 988
GHSA-cmmh-8mwp-gq5p
Drupal Cross Site Scripting (XSS) vulnerability
GHSA-ch7c-r59p-c6q5
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.
GHSA-cfh2-7f6h-3m85
Access bypass in Drupal Core
GHSA-c9jq-ww5c-g3v9
SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.
GHSA-c6j8-r888-r854
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.
GHSA-c533-c843-67h8
Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor
GHSA-c33g-h7g2-frf6
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
GHSA-9x6f-gcx8-396p
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.
GHSA-9p8g-gj5w-ghcm
Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information.
GHSA-9f2c-79x6-jgvf
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
GHSA-9c24-g32g-35rj
Drupal PECL YAML parser unsafe object handling
GHSA-98w5-wqp9-w466
Drupal Incorrect cache context on password reset page
GHSA-97r6-hfxf-q692
Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
GHSA-96vx-qf28-6f8m
Drupal Access Control Bypass
GHSA-966g-5893-w2jh
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
GHSA-95xj-v76h-9x4x
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
GHSA-9546-4cjm-mm4j
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
GHSA-938f-5r4f-h65v
Drupal core contains a potential PHP Object Injection vulnerability
GHSA-8wp5-373j-qw7h
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.
GHSA-8qf4-w3v3-j532
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-cmmh-8mwp-gq5p Drupal Cross Site Scripting (XSS) vulnerability | CVSS3: 5.4 | 55% Средний | больше 3 лет назад | |
GHSA-ch7c-r59p-c6q5 Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. | 0% Низкий | больше 3 лет назад | ||
GHSA-cfh2-7f6h-3m85 Access bypass in Drupal Core | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-c9jq-ww5c-g3v9 SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc. | 1% Низкий | больше 3 лет назад | ||
GHSA-c6j8-r888-r854 The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page. | 0% Низкий | больше 3 лет назад | ||
GHSA-c533-c843-67h8 Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor | CVSS3: 6.1 | 1% Низкий | почти 4 года назад | |
GHSA-c33g-h7g2-frf6 Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label. | 0% Низкий | больше 3 лет назад | ||
GHSA-9x6f-gcx8-396p The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue. | 0% Низкий | больше 3 лет назад | ||
GHSA-9p8g-gj5w-ghcm Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information. | 1% Низкий | больше 3 лет назад | ||
GHSA-9f2c-79x6-jgvf Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack. | 0% Низкий | больше 3 лет назад | ||
GHSA-9c24-g32g-35rj Drupal PECL YAML parser unsafe object handling | CVSS3: 9.8 | 67% Средний | больше 3 лет назад | |
GHSA-98w5-wqp9-w466 Drupal Incorrect cache context on password reset page | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-97r6-hfxf-q692 Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-96vx-qf28-6f8m Drupal Access Control Bypass | 1% Низкий | больше 3 лет назад | ||
GHSA-966g-5893-w2jh Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities. | 0% Низкий | больше 3 лет назад | ||
GHSA-95xj-v76h-9x4x The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message. | 0% Низкий | больше 3 лет назад | ||
GHSA-9546-4cjm-mm4j Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 1% Низкий | больше 3 лет назад | ||
GHSA-938f-5r4f-h65v Drupal core contains a potential PHP Object Injection vulnerability | CVSS3: 9.8 | 4% Низкий | около 1 года назад | |
GHSA-8wp5-373j-qw7h Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist. | 1% Низкий | больше 3 лет назад | ||
GHSA-8qf4-w3v3-j532 Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу