Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 012

Количество 2 012

github логотип

GHSA-7pvf-533w-5xpj

около 4 лет назад

Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."

EPSS: Низкий
github логотип

GHSA-7jr4-hgqx-vwgq

больше 3 лет назад

Access bypass in Drupal core

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-7j65-7v4p-q259

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.

EPSS: Низкий
github логотип

GHSA-7fh9-933g-885p

около 4 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-7ffh-cjvg-fpr4

около 4 лет назад

Drupal Settings Tray access bypass

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7ffg-g538-4c8c

около 4 лет назад

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.

EPSS: Низкий
github логотип

GHSA-7ff4-pff4-jj4c

около 4 лет назад

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

EPSS: Низкий
github логотип

GHSA-7cwc-fjqm-8vh8

больше 1 года назад

Drupal core Access bypass

EPSS: Низкий
github логотип

GHSA-784p-f8qg-9fqj

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.

EPSS: Низкий
github логотип

GHSA-7638-p5r3-r7hq

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-73q4-j324-2qcc

больше 4 лет назад

Incorrect authorization in Drupal core

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-6x23-g67f-x44h

около 4 лет назад

Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal.

EPSS: Низкий
github логотип

GHSA-6vg8-8jg2-mmpm

около 4 лет назад

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

EPSS: Низкий
github логотип

GHSA-6rmq-x2hv-vxpp

больше 6 лет назад

Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-6jcc-mv8v-q34f

около 4 лет назад

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.

EPSS: Низкий
github логотип

GHSA-6hpj-9xj7-2jxx

около 4 лет назад

Drupal access control bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6gwp-wc84-3h4m

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-6g9h-6v79-w4pc

около 4 лет назад

Drupal Users without "Administer comments" can set comment visibility on nodes they can edit

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6cj8-c359-p7q9

около 4 лет назад

Drupal vulnerable to Cross-site Scripting

EPSS: Низкий
github логотип

GHSA-69w7-38mj-9qxx

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7pvf-533w-5xpj

Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."

2%
Низкий
около 4 лет назад
github логотип
GHSA-7jr4-hgqx-vwgq

Access bypass in Drupal core

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7j65-7v4p-q259

Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7fh9-933g-885p

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
100%
Критический
около 4 лет назад
github логотип
GHSA-7ffh-cjvg-fpr4

Drupal Settings Tray access bypass

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-7ffg-g538-4c8c

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and successfully login via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-7ff4-pff4-jj4c

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

2%
Низкий
около 4 лет назад
github логотип
GHSA-7cwc-fjqm-8vh8

Drupal core Access bypass

0%
Низкий
больше 1 года назад
github логотип
GHSA-784p-f8qg-9fqj

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.2 allow remote attackers to (1) delete comments, (2) delete content revisions, and (3) disable menu items as privileged users, related to improper use of HTTP GET and the Forms API.

1%
Низкий
около 4 лет назад
github логотип
GHSA-7638-p5r3-r7hq

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-73q4-j324-2qcc

Incorrect authorization in Drupal core

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-6x23-g67f-x44h

Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal.

4%
Низкий
около 4 лет назад
github логотип
GHSA-6vg8-8jg2-mmpm

Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.

3%
Низкий
около 4 лет назад
github логотип
GHSA-6rmq-x2hv-vxpp

Drupal core third-party PEAR Archive_Tar library is vulnerable to Deserialization of Untrusted Data

CVSS3: 8
2%
Низкий
больше 6 лет назад
github логотип
GHSA-6jcc-mv8v-q34f

Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.

1%
Низкий
около 4 лет назад
github логотип
GHSA-6hpj-9xj7-2jxx

Drupal access control bypass vulnerability

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-6gwp-wc84-3h4m

Cross-site request forgery (CSRF) vulnerability in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-6g9h-6v79-w4pc

Drupal Users without "Administer comments" can set comment visibility on nodes they can edit

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-6cj8-c359-p7q9

Drupal vulnerable to Cross-site Scripting

2%
Низкий
около 4 лет назад
github логотип
GHSA-69w7-38mj-9qxx

Multiple cross-site scripting (XSS) vulnerabilities in the XML parser in Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allow remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу