Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

debian логотип

CVE-2014-9016

больше 10 лет назад

The password hashing API in Drupal 7.x before 7.34 and the Secure Pass ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2014-5266

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
EPSS: Высокий
nvd логотип

CVE-2014-5266

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
EPSS: Высокий
debian логотип

CVE-2014-5266

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2014-5265

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-5265

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-5265

почти 11 лет назад

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-1611

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-7302

около 11 лет назад

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-7067

больше 11 лет назад

The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows remote attackers to bypass intended access restrictions via a request.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-7067

больше 11 лет назад

The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows remote attackers to bypass intended access restrictions via a request.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-5965

больше 11 лет назад

The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-5964

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-5938

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5937

почти 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-5315

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than CVE-2013-4174.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-4504

около 11 лет назад

The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2013-4502

около 11 лет назад

The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-4498

около 11 лет назад

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-4446

больше 11 лет назад

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2014-9016

The password hashing API in Drupal 7.x before 7.34 and the Secure Pass ...

CVSS2: 5
80%
Высокий
больше 10 лет назад
ubuntu логотип
CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
77%
Высокий
почти 11 лет назад
nvd логотип
CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

CVSS2: 5
77%
Высокий
почти 11 лет назад
debian логотип
CVE-2014-5266

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
77%
Высокий
почти 11 лет назад
ubuntu логотип
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

CVSS2: 5
7%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-5265

The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 a ...

CVSS2: 5
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-1611

Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.

CVSS2: 4.3
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-7302

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

CVSS2: 6.8
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2013-7067

The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows remote attackers to bypass intended access restrictions via a request.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-7067

The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows remote attackers to bypass intended access restrictions via a request.

CVSS2: 5.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-5965

The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing.

CVSS2: 5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-5964

Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-5938

Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form.

CVSS2: 4.3
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5937

Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

CVSS2: 6.8
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-5315

Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6.x-1.x before 6.x-1.0-beta3 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the atom title, a different vector than CVE-2013-4174.

CVSS2: 2.6
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2013-4504

The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.

CVSS2: 2.6
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-4502

The FileField Sources module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.9 for Drupal does not properly check file permissions, which allows remote authenticated users to read arbitrary files by attaching a file.

CVSS2: 4
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-4498

The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

CVSS2: 2.1
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2013-4446

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support the json_decode function, allows remote attackers to execute arbitrary PHP code via unspecified vectors related to Ajax operations, possibly involving eval injection.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу