Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 012

Количество 2 012

github логотип

GHSA-42mr-w3cr-f7h3

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

EPSS: Низкий
github логотип

GHSA-3xr3-phjp-g6p2

больше 4 лет назад

Drupal core access bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v66-h3rq-pj5p

больше 4 лет назад

drupal6 version 6.16 has open redirection

EPSS: Низкий
github логотип

GHSA-3rm3-gj9m-589h

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

EPSS: Низкий
github логотип

GHSA-3px9-8vx9-h7qg

около 4 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

EPSS: Низкий
github логотип

GHSA-3ppx-frr2-xwmr

около 4 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3m36-mjwj-352c

больше 4 лет назад

Drupal core Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h3p-vm3f-v359

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gx6-h57h-rm27

около 4 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-3gw2-26w5-pcm6

больше 4 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

EPSS: Низкий
github логотип

GHSA-3crq-c4rc-qm8q

около 4 лет назад

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

EPSS: Низкий
github логотип

GHSA-39g6-x4x8-5jcm

больше 1 года назад

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3837-2vcf-c962

около 4 лет назад

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-337j-2h57-4h8m

около 4 лет назад

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

EPSS: Низкий
github логотип

GHSA-3327-jr93-7hq3

около 4 лет назад

Drupal access bypass vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qph-q8xw-gv7q

больше 1 года назад

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

EPSS: Низкий
github логотип

GHSA-2p28-5mvp-2j2r

около 4 лет назад

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2gh8-q6wj-fwpq

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

EPSS: Низкий
github логотип

GHSA-2fqf-xc87-725c

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

EPSS: Низкий
github логотип

GHSA-297x-j9pm-xjgg

больше 2 лет назад

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42mr-w3cr-f7h3

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3xr3-phjp-g6p2

Drupal core access bypass vulnerability

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v66-h3rq-pj5p

drupal6 version 6.16 has open redirection

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rm3-gj9m-589h

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3px9-8vx9-h7qg

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

4%
Низкий
около 4 лет назад
github логотип
GHSA-3ppx-frr2-xwmr

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3m36-mjwj-352c

Drupal core Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3h3p-vm3f-v359

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gx6-h57h-rm27

Drupal Core Remote Code Execution Vulnerability

CVSS3: 8.1
92%
Критический
около 4 лет назад
github логотип
GHSA-3gw2-26w5-pcm6

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3crq-c4rc-qm8q

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

2%
Низкий
около 4 лет назад
github логотип
GHSA-39g6-x4x8-5jcm

Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3837-2vcf-c962

Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-337j-2h57-4h8m

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3327-jr93-7hq3

Drupal access bypass vulnerability

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2qph-q8xw-gv7q

Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability

1%
Низкий
больше 1 года назад
github логотип
GHSA-2p28-5mvp-2j2r

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2gh8-q6wj-fwpq

Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2fqf-xc87-725c

Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

1%
Низкий
около 4 лет назад
github логотип
GHSA-297x-j9pm-xjgg

Drupal Core Remote Code Execution Vulnerability

CVSS3: 9.8
99%
Критический
больше 2 лет назад

Уязвимостей на страницу