Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-c9jq-ww5c-g3v9

около 3 лет назад

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

EPSS: Низкий
github логотип

GHSA-c6j8-r888-r854

около 3 лет назад

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.

EPSS: Низкий
github логотип

GHSA-c533-c843-67h8

больше 3 лет назад

Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c33g-h7g2-frf6

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

EPSS: Низкий
github логотип

GHSA-9x6f-gcx8-396p

около 3 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

EPSS: Низкий
github логотип

GHSA-9p8g-gj5w-ghcm

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-9f2c-79x6-jgvf

около 3 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

EPSS: Низкий
github логотип

GHSA-9c24-g32g-35rj

около 3 лет назад

Drupal PECL YAML parser unsafe object handling

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-98w5-wqp9-w466

около 3 лет назад

Drupal Incorrect cache context on password reset page

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-97r6-hfxf-q692

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-96vx-qf28-6f8m

около 3 лет назад

Drupal Access Control Bypass

EPSS: Низкий
github логотип

GHSA-966g-5893-w2jh

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

EPSS: Низкий
github логотип

GHSA-95xj-v76h-9x4x

около 3 лет назад

The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-9546-4cjm-mm4j

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-938f-5r4f-h65v

6 месяцев назад

Drupal core contains a potential PHP Object Injection vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8wp5-373j-qw7h

около 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

EPSS: Низкий
github логотип

GHSA-8qf4-w3v3-j532

около 3 лет назад

Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.

EPSS: Низкий
github логотип

GHSA-8q2j-8pc6-8c5r

около 3 лет назад

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

EPSS: Низкий
github логотип

GHSA-8mvq-8h2v-j9vf

6 месяцев назад

Drupal Core Cross-Site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8jj2-x2gc-ggm7

около 3 лет назад

Drupal Core Cross-site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c9jq-ww5c-g3v9

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

1%
Низкий
около 3 лет назад
github логотип
GHSA-c6j8-r888-r854

The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.

0%
Низкий
около 3 лет назад
github логотип
GHSA-c533-c843-67h8

Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c33g-h7g2-frf6

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

0%
Низкий
около 3 лет назад
github логотип
GHSA-9x6f-gcx8-396p

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

0%
Низкий
около 3 лет назад
github логотип
GHSA-9p8g-gj5w-ghcm

Multiple cross-site scripting (XSS) vulnerabilities in Drupal before 4.6.11, and 4.7 before 4.7.5, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in the (1) filter and (2) system modules. NOTE: some of these details are obtained from third party information.

1%
Низкий
около 3 лет назад
github логотип
GHSA-9f2c-79x6-jgvf

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

0%
Низкий
около 3 лет назад
github логотип
GHSA-9c24-g32g-35rj

Drupal PECL YAML parser unsafe object handling

CVSS3: 9.8
68%
Средний
около 3 лет назад
github логотип
GHSA-98w5-wqp9-w466

Drupal Incorrect cache context on password reset page

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-97r6-hfxf-q692

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-96vx-qf28-6f8m

Drupal Access Control Bypass

1%
Низкий
около 3 лет назад
github логотип
GHSA-966g-5893-w2jh

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

0%
Низкий
около 3 лет назад
github логотип
GHSA-95xj-v76h-9x4x

The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.

1%
Низкий
около 3 лет назад
github логотип
GHSA-9546-4cjm-mm4j

Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

1%
Низкий
около 3 лет назад
github логотип
GHSA-938f-5r4f-h65v

Drupal core contains a potential PHP Object Injection vulnerability

CVSS3: 9.8
3%
Низкий
6 месяцев назад
github логотип
GHSA-8wp5-373j-qw7h

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.

1%
Низкий
около 3 лет назад
github логотип
GHSA-8qf4-w3v3-j532

Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.

0%
Низкий
около 3 лет назад
github логотип
GHSA-8q2j-8pc6-8c5r

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.

0%
Низкий
около 3 лет назад
github логотип
GHSA-8mvq-8h2v-j9vf

Drupal Core Cross-Site Scripting (XSS)

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-8jj2-x2gc-ggm7

Drupal Core Cross-site scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад

Уязвимостей на страницу