Количество 1 966
Количество 1 966
GHSA-8j8f-9c88-qr6w
The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.
GHSA-8cw5-rv98-5c46
Arbitrary PHP code execution in Drupal
GHSA-8849-cv9f-vccm
Access bypass in Drupal core
GHSA-86rq-j7qh-jccc
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
GHSA-836p-6p4j-35cg
Drupal Open Redirect
GHSA-8335-5x6w-v3pw
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.
GHSA-82c6-j98m-2vfw
Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.
GHSA-7q56-gvfr-6f9w
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
GHSA-7pvf-533w-5xpj
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."
GHSA-7jr4-hgqx-vwgq
Access bypass in Drupal core
GHSA-7j65-7v4p-q259
Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.
GHSA-7fh9-933g-885p
Drupal Core Remote Code Execution Vulnerability
GHSA-7ffh-cjvg-fpr4
Drupal Settings Tray access bypass
GHSA-7ffg-g538-4c8c
The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.
GHSA-7ff4-pff4-jj4c
Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.
GHSA-7cwc-fjqm-8vh8
Drupal core Access bypass
GHSA-784p-f8qg-9fqj
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.
GHSA-7638-p5r3-r7hq
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.
GHSA-73q4-j324-2qcc
Incorrect authorization in Drupal core
GHSA-6x23-g67f-x44h
Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-8j8f-9c88-qr6w The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions. | 1% Низкий | около 3 лет назад | ||
GHSA-8cw5-rv98-5c46 Arbitrary PHP code execution in Drupal | CVSS3: 9.8 | 77% Высокий | больше 3 лет назад | |
GHSA-8849-cv9f-vccm Access bypass in Drupal core | 0% Низкий | около 2 лет назад | ||
GHSA-86rq-j7qh-jccc Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence. | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-836p-6p4j-35cg Drupal Open Redirect | CVSS3: 7.4 | 1% Низкий | около 3 лет назад | |
GHSA-8335-5x6w-v3pw Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements. | 0% Низкий | около 3 лет назад | ||
GHSA-82c6-j98m-2vfw Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements. | 0% Низкий | около 3 лет назад | ||
GHSA-7q56-gvfr-6f9w modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document. | 1% Низкий | около 3 лет назад | ||
GHSA-7pvf-533w-5xpj Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly." | 1% Низкий | около 3 лет назад | ||
GHSA-7jr4-hgqx-vwgq Access bypass in Drupal core | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-7j65-7v4p-q259 Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field. | 0% Низкий | около 3 лет назад | ||
GHSA-7fh9-933g-885p Drupal Core Remote Code Execution Vulnerability | CVSS3: 9.8 | 94% Критический | около 3 лет назад | |
GHSA-7ffh-cjvg-fpr4 Drupal Settings Tray access bypass | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-7ffg-g538-4c8c The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-7ff4-pff4-jj4c Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier. | 2% Низкий | около 3 лет назад | ||
GHSA-7cwc-fjqm-8vh8 Drupal core Access bypass | 0% Низкий | 6 месяцев назад | ||
GHSA-784p-f8qg-9fqj Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API. | 0% Низкий | около 3 лет назад | ||
GHSA-7638-p5r3-r7hq Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-73q4-j324-2qcc Incorrect authorization in Drupal core | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-6x23-g67f-x44h Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal. | 4% Низкий | около 3 лет назад |
Уязвимостей на страницу