Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

github логотип

GHSA-464x-pxv9-7m7h

больше 3 лет назад

The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-458j-vj9v-25r8

почти 4 года назад

Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-4537-mgq5-cjx2

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the _hosting_task_log_table function in modules/hosting/task/hosting_task.module in the Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a Drush log message in a provision task log.

EPSS: Низкий
github логотип

GHSA-449h-xgpj-vjvh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via the Maxpanel token.

EPSS: Низкий
github логотип

GHSA-43qw-p4wg-qvxr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.

EPSS: Низкий
github логотип

GHSA-43jr-gj2x-p9c9

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

EPSS: Низкий
github логотип

GHSA-42fx-xh6m-j2c4

больше 3 лет назад

The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.

EPSS: Низкий
github логотип

GHSA-428w-w772-h8gm

больше 3 лет назад

The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3x4f-24vq-5mhp

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3wxv-wgwg-qwjr

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.

EPSS: Низкий
github логотип

GHSA-3vmh-q3w3-vrjg

больше 3 лет назад

The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.

EPSS: Низкий
github логотип

GHSA-3vhp-rg2j-vwx8

больше 3 лет назад

The Contact Forms module 7.x-1.x before 7.x-1.2 for Drupal does not specify sufficiently restrictive permissions, which allows remote authenticated users with the "access the site-wide contact form" permission to modify the module settings via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3v8f-pqw4-37vx

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3v57-5947-5vgp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3rh8-f4gv-8c37

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.

EPSS: Низкий
github логотип

GHSA-3rcv-jp3w-f98g

больше 3 лет назад

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

EPSS: Низкий
github логотип

GHSA-3r52-23hx-qw5v

почти 4 года назад

Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-3mj3-396v-7f8p

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3m86-93x9-px5r

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form.

EPSS: Низкий
github логотип

GHSA-3jjw-w3h4-qj5p

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-464x-pxv9-7m7h

The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-458j-vj9v-25r8

Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4537-mgq5-cjx2

Cross-site scripting (XSS) vulnerability in the _hosting_task_log_table function in modules/hosting/task/hosting_task.module in the Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a Drush log message in a provision task log.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-449h-xgpj-vjvh

Cross-site scripting (XSS) vulnerability in the Mixpanel module 6.x-1.x before 6.x-1.1 in Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via the Maxpanel token.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43qw-p4wg-qvxr

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via an entity bundle label.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-43jr-gj2x-p9c9

Multiple cross-site scripting (XSS) vulnerabilities in the Colorbox Node module 7.x-2.x before 7.x-2.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42fx-xh6m-j2c4

The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-428w-w772-h8gm

The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x4f-24vq-5mhp

Multiple cross-site scripting (XSS) vulnerabilities in the Aggregation module 5.x before 5.x-4.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wxv-wgwg-qwjr

Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vmh-q3w3-vrjg

The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vhp-rg2j-vwx8

The Contact Forms module 7.x-1.x before 7.x-1.2 for Drupal does not specify sufficiently restrictive permissions, which allows remote authenticated users with the "access the site-wide contact form" permission to modify the module settings via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v8f-pqw4-37vx

Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3v57-5947-5vgp

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rh8-f4gv-8c37

Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rcv-jp3w-f98g

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r52-23hx-qw5v

Multiple unspecified vulnerabilities in the Node Browser module for Drupal have unknown impact and attack vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mj3-396v-7f8p

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3m86-93x9-px5r

Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jjw-w3h4-qj5p

Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу