Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

nvd логотип

CVE-2013-0325

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0324

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link title.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0323

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0322

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0321

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0320

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2013-0319

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0318

почти 13 лет назад

The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2013-0317

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0260

почти 13 лет назад

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0259

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0258

почти 13 лет назад

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-0257

почти 13 лет назад

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0227

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0225

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2013-0224

почти 13 лет назад

The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2013-0207

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-0206

почти 13 лет назад

Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2013-0205

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-0182

почти 13 лет назад

The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2013-0325

Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0324

Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link title.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0323

Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0322

Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0321

Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0320

Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.

CVSS2: 5.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0319

Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0318

The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.

CVSS2: 10
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0317

Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0260

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0259

Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0258

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0257

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0227

Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0225

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0224

The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.

CVSS2: 4.4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0207

Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0206

Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

CVSS2: 6
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0205

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-0182

The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.

CVSS2: 5
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу