Количество 1 966
Количество 1 966
GHSA-52jr-x6h6-xj6g
Drupal core vulnerable to improper error handling
GHSA-4xjq-cvhj-5j9x
Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
GHSA-4wfq-jc9h-vpcx
Lack of domain validation in Druple core
GHSA-4vf7-r26x-78hg
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."
GHSA-4jgw-6462-7fw2
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."
GHSA-4gh5-3hqj-x3pj
Drupal Form API ignores access restrictions on submit buttons
GHSA-47ww-rwmh-8q3w
Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.
GHSA-4588-3gxf-rhp2
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
GHSA-42mr-w3cr-f7h3
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
GHSA-3xr3-phjp-g6p2
Drupal core access bypass vulnerability
GHSA-3v66-h3rq-pj5p
drupal6 version 6.16 has open redirection
GHSA-3rm3-gj9m-589h
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
GHSA-3px9-8vx9-h7qg
Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
GHSA-3ppx-frr2-xwmr
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.
GHSA-3m36-mjwj-352c
Drupal core Cross-site Scripting (XSS) vulnerability
GHSA-3h3p-vm3f-v359
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.
GHSA-3gx6-h57h-rm27
Drupal Core Remote Code Execution Vulnerability
GHSA-3gw2-26w5-pcm6
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
GHSA-3crq-c4rc-qm8q
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.
GHSA-39g6-x4x8-5jcm
Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-52jr-x6h6-xj6g Drupal core vulnerable to improper error handling | CVSS3: 5.9 | 0% Низкий | 7 месяцев назад | |
GHSA-4xjq-cvhj-5j9x Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs. | 0% Низкий | около 3 лет назад | ||
GHSA-4wfq-jc9h-vpcx Lack of domain validation in Druple core | CVSS3: 6.1 | 1% Низкий | около 2 лет назад | |
GHSA-4vf7-r26x-78hg Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions." | 1% Низкий | около 3 лет назад | ||
GHSA-4jgw-6462-7fw2 The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error." | 0% Низкий | около 3 лет назад | ||
GHSA-4gh5-3hqj-x3pj Drupal Form API ignores access restrictions on submit buttons | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-47ww-rwmh-8q3w Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS. | 0% Низкий | около 3 лет назад | ||
GHSA-4588-3gxf-rhp2 Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack. | 0% Низкий | около 3 лет назад | ||
GHSA-42mr-w3cr-f7h3 Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview. | 0% Низкий | около 3 лет назад | ||
GHSA-3xr3-phjp-g6p2 Drupal core access bypass vulnerability | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3v66-h3rq-pj5p drupal6 version 6.16 has open redirection | 1% Низкий | около 3 лет назад | ||
GHSA-3rm3-gj9m-589h Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name. | 0% Низкий | около 3 лет назад | ||
GHSA-3px9-8vx9-h7qg Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743. | 4% Низкий | около 3 лет назад | ||
GHSA-3ppx-frr2-xwmr The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-3m36-mjwj-352c Drupal core Cross-site Scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3h3p-vm3f-v359 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102. | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад | |
GHSA-3gx6-h57h-rm27 Drupal Core Remote Code Execution Vulnerability | CVSS3: 8.1 | 94% Критический | около 3 лет назад | |
GHSA-3gw2-26w5-pcm6 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | 1% Низкий | около 3 лет назад | ||
GHSA-3crq-c4rc-qm8q The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types. | 1% Низкий | около 3 лет назад | ||
GHSA-39g6-x4x8-5jcm Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages | CVSS3: 6.1 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу