Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

nvd логотип

CVE-2013-1779

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-1778

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-1393

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the CurvyCorners module 6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with the "administer curvycorners" permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0325

около 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0324

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link title.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0323

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0322

около 12 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0321

около 12 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0320

около 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2013-0319

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0318

около 12 лет назад

The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2013-0317

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0260

около 12 лет назад

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0259

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0258

около 12 лет назад

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-0257

около 12 лет назад

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0227

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0225

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0224

больше 12 лет назад

The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2013-0207

больше 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2013-1779

Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-1778

Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

CVSS2: 2.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-1393

Cross-site scripting (XSS) vulnerability in the CurvyCorners module 6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with the "administer curvycorners" permission to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 2.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0325

Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0324

Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link title.

CVSS2: 2.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0323

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0322

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0321

Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0320

Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.

CVSS2: 5.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0319

Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0318

The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.

CVSS2: 10
1%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0317

Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.

CVSS2: 4.3
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0260

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

CVSS2: 2.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0259

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 2.1
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0258

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

CVSS2: 6.8
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0257

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

CVSS2: 5
0%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-0227

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0225

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0224

The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.

CVSS2: 4.4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-0207

Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу