Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

nvd логотип

CVE-2010-4520

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-4520

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-4519

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-4519

больше 14 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2010-3686

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3686

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3686

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-3685

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3685

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3685

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3423

почти 15 лет назад

SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3091

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-3091

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-3091

больше 14 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2724

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2010-2353

около 15 лет назад

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-2353

около 15 лет назад

The Node Reference module in Content Construction Kit (CCK) module 6.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2352

около 15 лет назад

The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-2352

около 15 лет назад

The Node Reference module in Content Construction Kit (CCK) module 5.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2158

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-4520

Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4520

Multiple cross-site scripting (XSS) vulnerabilities in the Views modul ...

CVSS2: 4.3
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-4519

Multiple cross-site request forgery (CSRF) vulnerabilities in the View ...

CVSS2: 6.8
0%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-3423

SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.

CVSS2: 7.5
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

CVSS2: 5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x ...

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2010-2724

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form.

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-2353

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

CVSS2: 5
1%
Низкий
около 15 лет назад
debian логотип
CVE-2010-2353

The Node Reference module in Content Construction Kit (CCK) module 6.x ...

CVSS2: 5
1%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-2352

The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes.

CVSS2: 5
1%
Низкий
около 15 лет назад
debian логотип
CVE-2010-2352

The Node Reference module in Content Construction Kit (CCK) module 5.x ...

CVSS2: 5
1%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-2158

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 2.1
0%
Низкий
около 15 лет назад

Уязвимостей на страницу