Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

debian логотип

CVE-2020-13665

больше 4 лет назад

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:A ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2020-13664

больше 4 лет назад

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-13664

больше 4 лет назад

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-13664

больше 4 лет назад

Arbitrary PHP code execution vulnerability in Drupal Core under certai ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-13663

около 4 лет назад

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-13663

около 4 лет назад

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-13663

около 4 лет назад

Cross Site Request Forgery vulnerability in Drupal Core Form API does ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2020-13662

больше 4 лет назад

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-13662

больше 4 лет назад

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-13662

больше 4 лет назад

Open Redirect vulnerability in Drupal Core allows a user to be tricked ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-6342

около 5 лет назад

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-6342

около 5 лет назад

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-6342

около 5 лет назад

An access bypass vulnerability exists when the experimental Workspaces ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-6341

больше 6 лет назад

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
EPSS: Средний
nvd логотип

CVE-2019-6341

больше 6 лет назад

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
EPSS: Средний
debian логотип

CVE-2019-6341

больше 6 лет назад

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.1 ...

CVSS3: 5.4
EPSS: Средний
ubuntu логотип

CVE-2019-6340

больше 6 лет назад

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

CVSS3: 8.1
EPSS: Критический
nvd логотип

CVE-2019-6340

больше 6 лет назад

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

CVSS3: 8.1
EPSS: Критический
debian логотип

CVE-2019-6340

больше 6 лет назад

Some field types do not properly sanitize data from non-form sources i ...

CVSS3: 8.1
EPSS: Критический
ubuntu логотип

CVE-2019-6339

больше 6 лет назад

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2020-13665

Access bypass vulnerability in Drupal Core allows JSON:API when JSON:A ...

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-13664

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-13664

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker could attempt to brute force a remote code execution vulnerability. Windows servers are most likely to be affected. This issue affects: Drupal Drupal Core 8.8.x versions prior to 8.8.8; 8.9.x versions prior to 8.9.1; 9.0.1 versions prior to 9.0.1.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-13664

Arbitrary PHP code execution vulnerability in Drupal Core under certai ...

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2020-13663

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2020-13663

Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
debian логотип
CVE-2020-13663

Cross Site Request Forgery vulnerability in Drupal Core Form API does ...

CVSS3: 8.8
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2020-13662

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2020-13662

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2020-13662

Open Redirect vulnerability in Drupal Core allows a user to be tricked ...

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2019-6342

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

CVSS3: 9.8
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2019-6342

An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

CVSS3: 9.8
0%
Низкий
около 5 лет назад
debian логотип
CVE-2019-6342

An access bypass vulnerability exists when the experimental Workspaces ...

CVSS3: 9.8
0%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2019-6341

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
55%
Средний
больше 6 лет назад
nvd логотип
CVE-2019-6341

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
55%
Средний
больше 6 лет назад
debian логотип
CVE-2019-6341

In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.1 ...

CVSS3: 5.4
55%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2019-6340

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

CVSS3: 8.1
94%
Критический
больше 6 лет назад
nvd логотип
CVE-2019-6340

Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following conditions is met: The site has the Drupal 8 core RESTful Web Services (rest) module enabled and allows PATCH or POST requests, or the site has another web services module enabled, like JSON:API in Drupal 8, or Services or RESTful Web Services in Drupal 7. (Note: The Drupal 7 Services module itself does not require an update at this time, but you should apply other contributed updates associated with this advisory if Services is in use.)

CVSS3: 8.1
94%
Критический
больше 6 лет назад
debian логотип
CVE-2019-6340

Some field types do not properly sanitize data from non-form sources i ...

CVSS3: 8.1
94%
Критический
больше 6 лет назад
ubuntu логотип
CVE-2019-6339

In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being exposed to this vulnerability. This vulnerability is mitigated by the fact that such code paths typically require access to an administrative permission or an atypical configuration.

CVSS3: 9.8
79%
Высокий
больше 6 лет назад

Уязвимостей на страницу