Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-52jr-x6h6-xj6g

7 месяцев назад

Drupal core vulnerable to improper error handling

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4xjq-cvhj-5j9x

около 3 лет назад

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

EPSS: Низкий
github логотип

GHSA-4wfq-jc9h-vpcx

около 2 лет назад

Lack of domain validation in Druple core

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vf7-r26x-78hg

около 3 лет назад

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

EPSS: Низкий
github логотип

GHSA-4jgw-6462-7fw2

около 3 лет назад

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

EPSS: Низкий
github логотип

GHSA-4gh5-3hqj-x3pj

около 3 лет назад

Drupal Form API ignores access restrictions on submit buttons

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-47ww-rwmh-8q3w

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

EPSS: Низкий
github логотип

GHSA-4588-3gxf-rhp2

около 3 лет назад

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

EPSS: Низкий
github логотип

GHSA-42mr-w3cr-f7h3

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

EPSS: Низкий
github логотип

GHSA-3xr3-phjp-g6p2

больше 3 лет назад

Drupal core access bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v66-h3rq-pj5p

около 3 лет назад

drupal6 version 6.16 has open redirection

EPSS: Низкий
github логотип

GHSA-3rm3-gj9m-589h

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

EPSS: Низкий
github логотип

GHSA-3px9-8vx9-h7qg

около 3 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

EPSS: Низкий
github логотип

GHSA-3ppx-frr2-xwmr

около 3 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3m36-mjwj-352c

больше 3 лет назад

Drupal core Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h3p-vm3f-v359

6 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gx6-h57h-rm27

около 3 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-3gw2-26w5-pcm6

около 3 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

EPSS: Низкий
github логотип

GHSA-3crq-c4rc-qm8q

около 3 лет назад

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

EPSS: Низкий
github логотип

GHSA-39g6-x4x8-5jcm

3 месяца назад

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52jr-x6h6-xj6g

Drupal core vulnerable to improper error handling

CVSS3: 5.9
0%
Низкий
7 месяцев назад
github логотип
GHSA-4xjq-cvhj-5j9x

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

0%
Низкий
около 3 лет назад
github логотип
GHSA-4wfq-jc9h-vpcx

Lack of domain validation in Druple core

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-4vf7-r26x-78hg

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

1%
Низкий
около 3 лет назад
github логотип
GHSA-4jgw-6462-7fw2

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

0%
Низкий
около 3 лет назад
github логотип
GHSA-4gh5-3hqj-x3pj

Drupal Form API ignores access restrictions on submit buttons

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-47ww-rwmh-8q3w

Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

0%
Низкий
около 3 лет назад
github логотип
GHSA-4588-3gxf-rhp2

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

0%
Низкий
около 3 лет назад
github логотип
GHSA-42mr-w3cr-f7h3

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3xr3-phjp-g6p2

Drupal core access bypass vulnerability

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v66-h3rq-pj5p

drupal6 version 6.16 has open redirection

1%
Низкий
около 3 лет назад
github логотип
GHSA-3rm3-gj9m-589h

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3px9-8vx9-h7qg

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

4%
Низкий
около 3 лет назад
github логотип
GHSA-3ppx-frr2-xwmr

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3m36-mjwj-352c

Drupal core Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h3p-vm3f-v359

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-3gx6-h57h-rm27

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
94%
Критический
около 3 лет назад
github логотип
GHSA-3gw2-26w5-pcm6

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

1%
Низкий
около 3 лет назад
github логотип
GHSA-3crq-c4rc-qm8q

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

1%
Низкий
около 3 лет назад
github логотип
GHSA-39g6-x4x8-5jcm

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
0%
Низкий
3 месяца назад

Уязвимостей на страницу