Количество 2 012
Количество 2 012
GHSA-97r6-hfxf-q692
Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
GHSA-96vx-qf28-6f8m
Drupal Access Control Bypass
GHSA-966g-5893-w2jh
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
GHSA-95xj-v76h-9x4x
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
GHSA-9546-4cjm-mm4j
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
GHSA-938f-5r4f-h65v
Drupal core contains a potential PHP Object Injection vulnerability
GHSA-8wp5-373j-qw7h
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist.
GHSA-8qf4-w3v3-j532
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.
GHSA-8q2j-8pc6-8c5r
The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values.
GHSA-8mvq-8h2v-j9vf
Drupal Core Cross-Site Scripting (XSS)
GHSA-8jj2-x2gc-ggm7
Drupal Core Cross-site scripting vulnerability
GHSA-8j8f-9c88-qr6w
The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions.
GHSA-8cw5-rv98-5c46
Arbitrary PHP code execution in Drupal
GHSA-8849-cv9f-vccm
Access bypass in Drupal core
GHSA-86rq-j7qh-jccc
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
GHSA-83v7-c2cf-p9c2
Drupal core allows Forceful Browsing
GHSA-836p-6p4j-35cg
Drupal Open Redirect
GHSA-8335-5x6w-v3pw
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.
GHSA-82c6-j98m-2vfw
Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.
GHSA-7q56-gvfr-6f9w
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-97r6-hfxf-q692 Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-96vx-qf28-6f8m Drupal Access Control Bypass | 3% Низкий | около 4 лет назад | ||
GHSA-966g-5893-w2jh Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities. | 1% Низкий | около 4 лет назад | ||
GHSA-95xj-v76h-9x4x The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message. | 3% Низкий | около 4 лет назад | ||
GHSA-9546-4cjm-mm4j Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-938f-5r4f-h65v Drupal core contains a potential PHP Object Injection vulnerability | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-8wp5-373j-qw7h Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter used in (2) label and (3) input tags, possibly due to an incomplete blacklist. | 1% Низкий | около 4 лет назад | ||
GHSA-8qf4-w3v3-j532 Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism. | 2% Низкий | около 4 лет назад | ||
GHSA-8q2j-8pc6-8c5r The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form, which allows remote authenticated users to bypass intended access restrictions via modified field values. | 1% Низкий | около 4 лет назад | ||
GHSA-8mvq-8h2v-j9vf Drupal Core Cross-Site Scripting (XSS) | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-8jj2-x2gc-ggm7 Drupal Core Cross-site scripting vulnerability | CVSS3: 6.1 | 3% Низкий | около 4 лет назад | |
GHSA-8j8f-9c88-qr6w The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allow attackers to bypass access restrictions and trigger e-mail with unpublished comments from some modules, as demonstrated by (1) Organic groups and (2) Subscriptions. | 1% Низкий | около 4 лет назад | ||
GHSA-8cw5-rv98-5c46 Arbitrary PHP code execution in Drupal | CVSS3: 9.8 | 33% Средний | больше 4 лет назад | |
GHSA-8849-cv9f-vccm Access bypass in Drupal core | 1% Низкий | больше 3 лет назад | ||
GHSA-86rq-j7qh-jccc Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-83v7-c2cf-p9c2 Drupal core allows Forceful Browsing | 0% Низкий | 8 месяцев назад | ||
GHSA-836p-6p4j-35cg Drupal Open Redirect | CVSS3: 7.4 | 2% Низкий | около 4 лет назад | |
GHSA-8335-5x6w-v3pw Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements. | 2% Низкий | около 4 лет назад | ||
GHSA-82c6-j98m-2vfw Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements. | 1% Низкий | около 4 лет назад | ||
GHSA-7q56-gvfr-6f9w modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document. | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу