Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

nvd логотип

CVE-2011-0771

больше 14 лет назад

The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-5277

почти 13 лет назад

Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2010-5276

почти 13 лет назад

The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-5275

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4813

около 14 лет назад

Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2010-4775

больше 14 лет назад

The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-4521

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4521

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the Views module 6.x befor ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4520

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4520

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4519

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-4519

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2010-3686

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3686

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3686

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-3685

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3685

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3685

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3423

почти 15 лет назад

SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3091

почти 15 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-0771

The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site.

CVSS2: 6.8
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-5277

Unspecified vulnerability in the Views Bulk Operations module 6 before 6.x-1.10 for Drupal allows remote authenticated users with user management permissions to bypass intended access restrictions and delete anonymous users (user 0) via unspecified vectors.

CVSS2: 4.9
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2010-5276

The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2010-5275

Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2010-4813

Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.

CVSS2: 3.5
0%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-4775

The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not properly implement node access logic, which allows remote attackers to discover restricted node titles and relationships.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4521

Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4521

Cross-site scripting (XSS) vulnerability in the Views module 6.x befor ...

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4520

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4520

Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3423

SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.

CVSS2: 7.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
почти 15 лет назад

Уязвимостей на страницу