Количество 2 012
Количество 2 012
GHSA-w3gp-frj6-h378
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.
GHSA-w2pj-c8x5-jvg2
Drupal File upload access bypass and denial of service
GHSA-vxwx-8gpv-2wr4
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
GHSA-vwxh-w8pq-6q99
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
GHSA-vqp6-f6x9-5r96
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
GHSA-vqfh-h9j7-97mw
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
GHSA-vpm6-h53m-x2xf
Drupal improper access restrictions
GHSA-vhg8-x858-7wq6
Drupal Cross-site scripting (XSS) vulnerability
GHSA-vh9v-98rp-w5wr
Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.
GHSA-vfw4-2ffw-69gw
The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."
GHSA-vf6r-36v5-6m37
Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.
GHSA-v8wr-r69p-mmwx
Unrestricted Upload of File with Dangerous Type in Drupal core
GHSA-v3f6-f29f-rgvp
Missing Authorization in Drupal
GHSA-v2j6-5f8p-jrqf
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.
GHSA-v259-f6cv-rqhc
Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.
GHSA-rrhw-3394-cj5f
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
GHSA-rq7c-6h8j-3jp6
Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
GHSA-rq65-q8rh-x7j3
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
GHSA-rpc3-pj28-4vq6
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
GHSA-rjqg-3h9m-fx5x
Cache poisoning in drupal/core
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-w3gp-frj6-h378 Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | 4% Низкий | больше 4 лет назад | ||
GHSA-w2pj-c8x5-jvg2 Drupal File upload access bypass and denial of service | CVSS3: 8.1 | 2% Низкий | около 4 лет назад | |
GHSA-vxwx-8gpv-2wr4 Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files. | 2% Низкий | около 4 лет назад | ||
GHSA-vwxh-w8pq-6q99 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. | CVSS3: 5.9 | 0% Низкий | 20 дней назад | |
GHSA-vqp6-f6x9-5r96 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | 1% Низкий | больше 4 лет назад | ||
GHSA-vqfh-h9j7-97mw Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules. | 2% Низкий | около 4 лет назад | ||
GHSA-vpm6-h53m-x2xf Drupal improper access restrictions | 2% Низкий | около 4 лет назад | ||
GHSA-vhg8-x858-7wq6 Drupal Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-vh9v-98rp-w5wr Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable. | 3% Низкий | около 4 лет назад | ||
GHSA-vfw4-2ffw-69gw The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks." | 1% Низкий | около 4 лет назад | ||
GHSA-vf6r-36v5-6m37 Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename. | 1% Низкий | около 4 лет назад | ||
GHSA-v8wr-r69p-mmwx Unrestricted Upload of File with Dangerous Type in Drupal core | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-v3f6-f29f-rgvp Missing Authorization in Drupal | CVSS3: 6.5 | 2% Низкий | почти 7 лет назад | |
GHSA-v2j6-5f8p-jrqf Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms. | 1% Низкий | около 4 лет назад | ||
GHSA-v259-f6cv-rqhc Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated. | 3% Низкий | около 4 лет назад | ||
GHSA-rrhw-3394-cj5f Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-rq7c-6h8j-3jp6 Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist. | 1% Низкий | около 4 лет назад | ||
GHSA-rq65-q8rh-x7j3 Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title. | 2% Низкий | около 4 лет назад | ||
GHSA-rpc3-pj28-4vq6 Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results. | 3% Низкий | около 4 лет назад | ||
GHSA-rjqg-3h9m-fx5x Cache poisoning in drupal/core | 1% Низкий | почти 3 года назад |
Уязвимостей на страницу