Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

github логотип

GHSA-5jj7-fw29-87vx

больше 3 лет назад

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-5gv4-95g8-gfc6

больше 3 лет назад

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

EPSS: Низкий
github логотип

GHSA-58f3-cx8p-h8jg

больше 3 лет назад

Drupal core access bypass vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-585j-5449-mf5m

больше 3 лет назад

Drupal cross-site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-52jr-x6h6-xj6g

около 1 года назад

Drupal core vulnerable to improper error handling

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4xjq-cvhj-5j9x

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

EPSS: Низкий
github логотип

GHSA-4wfq-jc9h-vpcx

больше 2 лет назад

Lack of domain validation in Druple core

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vf7-r26x-78hg

больше 3 лет назад

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

EPSS: Низкий
github логотип

GHSA-4jgw-6462-7fw2

больше 3 лет назад

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

EPSS: Низкий
github логотип

GHSA-4gh5-3hqj-x3pj

больше 3 лет назад

Drupal Form API ignores access restrictions on submit buttons

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-47ww-rwmh-8q3w

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

EPSS: Низкий
github логотип

GHSA-4588-3gxf-rhp2

больше 3 лет назад

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

EPSS: Низкий
github логотип

GHSA-42mr-w3cr-f7h3

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

EPSS: Низкий
github логотип

GHSA-3xr3-phjp-g6p2

почти 4 года назад

Drupal core access bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v66-h3rq-pj5p

больше 3 лет назад

drupal6 version 6.16 has open redirection

EPSS: Низкий
github логотип

GHSA-3rm3-gj9m-589h

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

EPSS: Низкий
github логотип

GHSA-3px9-8vx9-h7qg

больше 3 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

EPSS: Низкий
github логотип

GHSA-3ppx-frr2-xwmr

больше 3 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3m36-mjwj-352c

почти 4 года назад

Drupal core Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h3p-vm3f-v359

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5jj7-fw29-87vx

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-5gv4-95g8-gfc6

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-58f3-cx8p-h8jg

Drupal core access bypass vulnerability

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-585j-5449-mf5m

Drupal cross-site scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-52jr-x6h6-xj6g

Drupal core vulnerable to improper error handling

CVSS3: 5.9
1%
Низкий
около 1 года назад
github логотип
GHSA-4xjq-cvhj-5j9x

Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4wfq-jc9h-vpcx

Lack of domain validation in Druple core

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vf7-r26x-78hg

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4jgw-6462-7fw2

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4gh5-3hqj-x3pj

Drupal Form API ignores access restrictions on submit buttons

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-47ww-rwmh-8q3w

Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4588-3gxf-rhp2

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42mr-w3cr-f7h3

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xr3-phjp-g6p2

Drupal core access bypass vulnerability

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3v66-h3rq-pj5p

drupal6 version 6.16 has open redirection

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rm3-gj9m-589h

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3px9-8vx9-h7qg

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3ppx-frr2-xwmr

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m36-mjwj-352c

Drupal core Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-3h3p-vm3f-v359

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVSS3: 6.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу