Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-vxwx-8gpv-2wr4

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.

EPSS: Низкий
github логотип

GHSA-vqp6-f6x9-5r96

около 3 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

EPSS: Низкий
github логотип

GHSA-vqfh-h9j7-97mw

около 3 лет назад

Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.

EPSS: Низкий
github логотип

GHSA-vpm6-h53m-x2xf

около 3 лет назад

Drupal improper access restrictions

EPSS: Низкий
github логотип

GHSA-vhg8-x858-7wq6

около 3 лет назад

Drupal Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vh9v-98rp-w5wr

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

EPSS: Низкий
github логотип

GHSA-vfw4-2ffw-69gw

около 3 лет назад

The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

EPSS: Низкий
github логотип

GHSA-vf6r-36v5-6m37

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

EPSS: Низкий
github логотип

GHSA-v8wr-r69p-mmwx

больше 3 лет назад

Unrestricted Upload of File with Dangerous Type in Drupal core

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v3f6-f29f-rgvp

больше 5 лет назад

Missing Authorization in Drupal

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v2j6-5f8p-jrqf

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.

EPSS: Низкий
github логотип

GHSA-v259-f6cv-rqhc

около 3 лет назад

Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.

EPSS: Низкий
github логотип

GHSA-rrhw-3394-cj5f

около 3 лет назад

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-rq7c-6h8j-3jp6

около 3 лет назад

Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.

EPSS: Низкий
github логотип

GHSA-rq65-q8rh-x7j3

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.

EPSS: Низкий
github логотип

GHSA-rpc3-pj28-4vq6

около 3 лет назад

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

EPSS: Низкий
github логотип

GHSA-rjqg-3h9m-fx5x

больше 1 года назад

Cache poisoning in drupal/core

EPSS: Низкий
github логотип

GHSA-rjjm-xf3c-gmh6

около 3 лет назад

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-rhx9-3qf7-r3j7

около 3 лет назад

Drupal Remote code execution

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-rfxx-gxwc-923c

около 3 лет назад

Drupal Views can allow unauthorized users to see Statistics information

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-vxwx-8gpv-2wr4

Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.

1%
Низкий
около 3 лет назад
github логотип
GHSA-vqp6-f6x9-5r96

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

0%
Низкий
около 3 лет назад
github логотип
GHSA-vqfh-h9j7-97mw

Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.

1%
Низкий
около 3 лет назад
github логотип
GHSA-vpm6-h53m-x2xf

Drupal improper access restrictions

0%
Низкий
около 3 лет назад
github логотип
GHSA-vhg8-x858-7wq6

Drupal Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-vh9v-98rp-w5wr

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

1%
Низкий
около 3 лет назад
github логотип
GHSA-vfw4-2ffw-69gw

The Form API in Drupal 6.x before 6.37 and 7.x before 7.39 does not properly validate the form token, which allows remote attackers to conduct CSRF attacks that upload files in a different user's account via vectors related to "file upload value callbacks."

0%
Низкий
около 3 лет назад
github логотип
GHSA-vf6r-36v5-6m37

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

1%
Низкий
около 3 лет назад
github логотип
GHSA-v8wr-r69p-mmwx

Unrestricted Upload of File with Dangerous Type in Drupal core

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-v3f6-f29f-rgvp

Missing Authorization in Drupal

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-v2j6-5f8p-jrqf

Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.

0%
Низкий
около 3 лет назад
github логотип
GHSA-v259-f6cv-rqhc

Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.

3%
Низкий
около 3 лет назад
github логотип
GHSA-rrhw-3394-cj5f

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-rq7c-6h8j-3jp6

Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.

1%
Низкий
около 3 лет назад
github логотип
GHSA-rq65-q8rh-x7j3

Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.

0%
Низкий
около 3 лет назад
github логотип
GHSA-rpc3-pj28-4vq6

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

1%
Низкий
около 3 лет назад
github логотип
GHSA-rjqg-3h9m-fx5x

Cache poisoning in drupal/core

2%
Низкий
больше 1 года назад
github логотип
GHSA-rjjm-xf3c-gmh6

The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-rhx9-3qf7-r3j7

Drupal Remote code execution

CVSS3: 8.1
5%
Низкий
около 3 лет назад
github логотип
GHSA-rfxx-gxwc-923c

Drupal Views can allow unauthorized users to see Statistics information

CVSS3: 5.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу