Количество 2 012
Количество 2 012
GHSA-6955-67hm-vjjq
Drupal core arbitrary PHP code execution
GHSA-68jc-v27h-vhmw
Drupal core Unrestricted Upload of File with Dangerous Type
GHSA-68h9-7525-2j7f
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
GHSA-66mv-q8r2-hj8w
Drupal access bypass vulnerability
GHSA-66gr-xrcf-8jpq
Drupal Open Redirect
GHSA-648w-fmj6-586x
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-62cf-jvpp-48q6
Drupal Denial of Service vulnerability
GHSA-5vpr-v24w-mmjj
Drupal cross site scripting vulnerability
GHSA-5jj7-fw29-87vx
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
GHSA-5gv4-95g8-gfc6
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
GHSA-58f3-cx8p-h8jg
Drupal core access bypass vulnerability
GHSA-585j-5449-mf5m
Drupal cross-site scripting vulnerability
GHSA-52jr-x6h6-xj6g
Drupal core vulnerable to improper error handling
GHSA-4xjq-cvhj-5j9x
Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
GHSA-4wfq-jc9h-vpcx
Lack of domain validation in Druple core
GHSA-4vf7-r26x-78hg
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."
GHSA-4jgw-6462-7fw2
The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error."
GHSA-4gh5-3hqj-x3pj
Drupal Form API ignores access restrictions on submit buttons
GHSA-47ww-rwmh-8q3w
Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.
GHSA-4588-3gxf-rhp2
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6955-67hm-vjjq Drupal core arbitrary PHP code execution | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-68jc-v27h-vhmw Drupal core Unrestricted Upload of File with Dangerous Type | CVSS3: 8.8 | 4% Низкий | почти 5 лет назад | |
GHSA-68h9-7525-2j7f install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified. | 4% Низкий | около 4 лет назад | ||
GHSA-66mv-q8r2-hj8w Drupal access bypass vulnerability | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-66gr-xrcf-8jpq Drupal Open Redirect | CVSS3: 6.8 | 2% Низкий | около 4 лет назад | |
GHSA-648w-fmj6-586x Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-62cf-jvpp-48q6 Drupal Denial of Service vulnerability | 1% Низкий | больше 2 лет назад | ||
GHSA-5vpr-v24w-mmjj Drupal cross site scripting vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-5jj7-fw29-87vx Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-5gv4-95g8-gfc6 The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache. | 2% Низкий | около 4 лет назад | ||
GHSA-58f3-cx8p-h8jg Drupal core access bypass vulnerability | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-585j-5449-mf5m Drupal cross-site scripting vulnerability | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-52jr-x6h6-xj6g Drupal core vulnerable to improper error handling | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-4xjq-cvhj-5j9x Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs. | 1% Низкий | около 4 лет назад | ||
GHSA-4wfq-jc9h-vpcx Lack of domain validation in Druple core | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-4vf7-r26x-78hg Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions." | 2% Низкий | около 4 лет назад | ||
GHSA-4jgw-6462-7fw2 The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restrictions and "attach files to content," related to a "logic error." | 1% Низкий | около 4 лет назад | ||
GHSA-4gh5-3hqj-x3pj Drupal Form API ignores access restrictions on submit buttons | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-47ww-rwmh-8q3w Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS. | 2% Низкий | около 4 лет назад | ||
GHSA-4588-3gxf-rhp2 Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack. | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу