Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

nvd логотип

CVE-2020-36193

около 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2020-36193

около 5 лет назад

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
EPSS: Критический
redhat логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.1
EPSS: Критический
nvd логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
EPSS: Критический
debian логотип

CVE-2020-28949

около 5 лет назад

Archive_Tar through 1.4.10 has :// filename sanitization only to addre ...

CVSS3: 7.8
EPSS: Критический
ubuntu логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Высокий
redhat логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Высокий
nvd логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
EPSS: Высокий
debian логотип

CVE-2020-28948

около 5 лет назад

Archive_Tar through 1.4.10 allows an unserialization attack because ph ...

CVSS3: 7.8
EPSS: Высокий
nvd логотип

CVE-2019-11876

больше 6 лет назад

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-10911

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-10911

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-10911

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10910

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2019-10910

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2019-10910

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2019-10909

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-10909

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-10909

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS3: 7.5
71%
Высокий
около 5 лет назад
debian логотип
CVE-2020-36193

Tar.php in Archive_Tar through 1.4.11 allows write operations with Dir ...

CVSS3: 7.5
71%
Высокий
около 5 лет назад
ubuntu логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
93%
Критический
около 5 лет назад
redhat логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.1
93%
Критический
около 5 лет назад
nvd логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

CVSS3: 7.8
93%
Критический
около 5 лет назад
debian логотип
CVE-2020-28949

Archive_Tar through 1.4.10 has :// filename sanitization only to addre ...

CVSS3: 7.8
93%
Критический
около 5 лет назад
ubuntu логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
76%
Высокий
около 5 лет назад
redhat логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
76%
Высокий
около 5 лет назад
nvd логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.

CVSS3: 7.8
76%
Высокий
около 5 лет назад
debian логотип
CVE-2020-28948

Archive_Tar through 1.4.10 allows an unserialization attack because ph ...

CVSS3: 7.8
76%
Высокий
около 5 лет назад
nvd логотип
CVE-2019-11876

In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and conditions) before executing the malicious link.

CVSS3: 6.1
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10910

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
13%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-10910

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS3: 9.8
13%
Средний
больше 6 лет назад
debian логотип
CVE-2019-10910

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 9.8
13%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2019-10909

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10909

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

CVSS3: 5.4
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10909

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...

CVSS3: 5.4
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу