Количество 1 966
Количество 1 966
GHSA-vxwx-8gpv-2wr4
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.
GHSA-vqp6-f6x9-5r96
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
GHSA-vqfh-h9j7-97mw
Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.
GHSA-vpm6-h53m-x2xf
Drupal improper access restrictions
GHSA-vhg8-x858-7wq6
Drupal Cross-site scripting (XSS) vulnerability
GHSA-vh9v-98rp-w5wr
Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.
GHSA-vfw4-2ffw-69gw
The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."
GHSA-vf6r-36v5-6m37
Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.
GHSA-v8wr-r69p-mmwx
Unrestricted Upload of File with Dangerous Type in Drupal core
GHSA-v3f6-f29f-rgvp
Missing Authorization in Drupal
GHSA-v2j6-5f8p-jrqf
Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.
GHSA-v259-f6cv-rqhc
Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.
GHSA-rrhw-3394-cj5f
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
GHSA-rq7c-6h8j-3jp6
Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.
GHSA-rq65-q8rh-x7j3
Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.
GHSA-rpc3-pj28-4vq6
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
GHSA-rjqg-3h9m-fx5x
Cache poisoning in drupal/core
GHSA-rjjm-xf3c-gmh6
The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.
GHSA-rhx9-3qf7-r3j7
Drupal Remote code execution
GHSA-rfxx-gxwc-923c
Drupal Views can allow unauthorized users to see Statistics information
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-vxwx-8gpv-2wr4 Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files. | 1% Низкий | около 3 лет назад | ||
GHSA-vqp6-f6x9-5r96 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | 0% Низкий | около 3 лет назад | ||
GHSA-vqfh-h9j7-97mw Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules. | 1% Низкий | около 3 лет назад | ||
GHSA-vpm6-h53m-x2xf Drupal improper access restrictions | 0% Низкий | около 3 лет назад | ||
GHSA-vhg8-x858-7wq6 Drupal Cross-site scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-vh9v-98rp-w5wr Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable. | 1% Низкий | около 3 лет назад | ||
GHSA-vfw4-2ffw-69gw The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks." | 0% Низкий | около 3 лет назад | ||
GHSA-vf6r-36v5-6m37 Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename. | 1% Низкий | около 3 лет назад | ||
GHSA-v8wr-r69p-mmwx Unrestricted Upload of File with Dangerous Type in Drupal core | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-v3f6-f29f-rgvp Missing Authorization in Drupal | CVSS3: 6.5 | 0% Низкий | больше 5 лет назад | |
GHSA-v2j6-5f8p-jrqf Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms. | 0% Низкий | около 3 лет назад | ||
GHSA-v259-f6cv-rqhc Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated. | 3% Низкий | около 3 лет назад | ||
GHSA-rrhw-3394-cj5f Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-rq7c-6h8j-3jp6 Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist. | 1% Низкий | около 3 лет назад | ||
GHSA-rq65-q8rh-x7j3 Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title. | 0% Низкий | около 3 лет назад | ||
GHSA-rpc3-pj28-4vq6 Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results. | 1% Низкий | около 3 лет назад | ||
GHSA-rjqg-3h9m-fx5x Cache poisoning in drupal/core | 2% Низкий | больше 1 года назад | ||
GHSA-rjjm-xf3c-gmh6 The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors. | 0% Низкий | около 3 лет назад | ||
GHSA-rhx9-3qf7-r3j7 Drupal Remote code execution | CVSS3: 8.1 | 5% Низкий | около 3 лет назад | |
GHSA-rfxx-gxwc-923c Drupal Views can allow unauthorized users to see Statistics information | CVSS3: 5.3 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу