Количество 2 012
Количество 2 012
GHSA-42mr-w3cr-f7h3
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
GHSA-3xr3-phjp-g6p2
Drupal core access bypass vulnerability
GHSA-3v66-h3rq-pj5p
drupal6 version 6.16 has open redirection
GHSA-3rm3-gj9m-589h
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
GHSA-3px9-8vx9-h7qg
Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.
GHSA-3ppx-frr2-xwmr
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.
GHSA-3m36-mjwj-352c
Drupal core Cross-site Scripting (XSS) vulnerability
GHSA-3h3p-vm3f-v359
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102.
GHSA-3gx6-h57h-rm27
Drupal Core Remote Code Execution Vulnerability
GHSA-3gw2-26w5-pcm6
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
GHSA-3crq-c4rc-qm8q
The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.
GHSA-39g6-x4x8-5jcm
Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages
GHSA-3837-2vcf-c962
Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.
GHSA-337j-2h57-4h8m
The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.
GHSA-3327-jr93-7hq3
Drupal access bypass vulnerability
GHSA-2qph-q8xw-gv7q
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
GHSA-2p28-5mvp-2j2r
Drupal Comment reply form allows access to restricted content
GHSA-2gh8-q6wj-fwpq
Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.
GHSA-2fqf-xc87-725c
Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.
GHSA-297x-j9pm-xjgg
Drupal Core Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-42mr-w3cr-f7h3 Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview. | 1% Низкий | около 4 лет назад | ||
GHSA-3xr3-phjp-g6p2 Drupal core access bypass vulnerability | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3v66-h3rq-pj5p drupal6 version 6.16 has open redirection | 1% Низкий | больше 4 лет назад | ||
GHSA-3rm3-gj9m-589h Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name. | 1% Низкий | около 4 лет назад | ||
GHSA-3px9-8vx9-h7qg Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743. | 4% Низкий | около 4 лет назад | ||
GHSA-3ppx-frr2-xwmr The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-3m36-mjwj-352c Drupal core Cross-site Scripting (XSS) vulnerability | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3h3p-vm3f-v359 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 7.0 before 7.102. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-3gx6-h57h-rm27 Drupal Core Remote Code Execution Vulnerability | CVSS3: 8.1 | 92% Критический | около 4 лет назад | |
GHSA-3gw2-26w5-pcm6 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | 1% Низкий | больше 4 лет назад | ||
GHSA-3crq-c4rc-qm8q The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types. | 2% Низкий | около 4 лет назад | ||
GHSA-39g6-x4x8-5jcm Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-3837-2vcf-c962 Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information. | 1% Низкий | около 4 лет назад | ||
GHSA-337j-2h57-4h8m The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML. | 1% Низкий | около 4 лет назад | ||
GHSA-3327-jr93-7hq3 Drupal access bypass vulnerability | CVSS3: 8.1 | 1% Низкий | около 4 лет назад | |
GHSA-2qph-q8xw-gv7q Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability | 1% Низкий | больше 1 года назад | ||
GHSA-2p28-5mvp-2j2r Drupal Comment reply form allows access to restricted content | CVSS3: 8.1 | 1% Низкий | около 4 лет назад | |
GHSA-2gh8-q6wj-fwpq Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table. | 1% Низкий | около 4 лет назад | ||
GHSA-2fqf-xc87-725c Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules. | 1% Низкий | около 4 лет назад | ||
GHSA-297x-j9pm-xjgg Drupal Core Remote Code Execution Vulnerability | CVSS3: 9.8 | 99% Критический | больше 2 лет назад |
Уязвимостей на страницу