Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-rcwp-vp94-qpq4

около 3 лет назад

The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.

EPSS: Низкий
github логотип

GHSA-qvqj-pfj9-vcvw

около 3 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

EPSS: Низкий
github логотип

GHSA-qr75-jf52-qrw8

около 3 лет назад

** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.

EPSS: Низкий
github логотип

GHSA-qqxc-cppg-4xp8

около 3 лет назад

Drupal Reflected file download vulnerability

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-qfhg-m6r8-xxpj

больше 3 лет назад

Incorrect Authorization in Drupal core

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-qf2g-mrrx-rr5p

около 3 лет назад

Drupal Core Cross-site scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q4hh-4qxq-c529

около 3 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Низкий
github логотип

GHSA-q3p9-8728-wq7x

около 3 лет назад

Drupal saving user accounts can sometimes grant the user all roles

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pw4m-g5pv-hrp6

около 3 лет назад

Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.

EPSS: Низкий
github логотип

GHSA-pqv4-xgqh-j8vh

около 3 лет назад

Drupal sensitive information disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-pp4m-6679-4g83

около 3 лет назад

The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

EPSS: Низкий
github логотип

GHSA-pjmx-4gc6-hwv8

около 3 лет назад

Drupal cross-site scripting vulnerability via actions feature and trigger module

EPSS: Низкий
github логотип

GHSA-phv5-85pf-xrp3

около 3 лет назад

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."

EPSS: Низкий
github логотип

GHSA-ph8m-2h2f-qgr2

около 3 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-ph2j-5hxq-gxrr

около 3 лет назад

Drupal Node Validation Bypass in the node module API

EPSS: Низкий
github логотип

GHSA-pgxv-w4j7-wh5m

около 3 лет назад

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

EPSS: Низкий
github логотип

GHSA-pfc2-6vvp-c5mq

около 3 лет назад

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

EPSS: Низкий
github логотип

GHSA-p8g6-5mg7-9r5q

около 3 лет назад

Drupal REST API can bypass comment approval

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-p745-347h-hjfw

около 3 лет назад

Drupal sensitive information disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-p6w6-6v99-r2gr

около 3 лет назад

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rcwp-vp94-qpq4

The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qvqj-pfj9-vcvw

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

1%
Низкий
около 3 лет назад
github логотип
GHSA-qr75-jf52-qrw8

** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.

0%
Низкий
около 3 лет назад
github логотип
GHSA-qqxc-cppg-4xp8

Drupal Reflected file download vulnerability

CVSS3: 6.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-qfhg-m6r8-xxpj

Incorrect Authorization in Drupal core

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-qf2g-mrrx-rr5p

Drupal Core Cross-site scripting vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-q4hh-4qxq-c529

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

2%
Низкий
около 3 лет назад
github логотип
GHSA-q3p9-8728-wq7x

Drupal saving user accounts can sometimes grant the user all roles

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-pw4m-g5pv-hrp6

Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.

1%
Низкий
около 3 лет назад
github логотип
GHSA-pqv4-xgqh-j8vh

Drupal sensitive information disclosure

CVSS3: 5.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-pp4m-6679-4g83

The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

0%
Низкий
около 3 лет назад
github логотип
GHSA-pjmx-4gc6-hwv8

Drupal cross-site scripting vulnerability via actions feature and trigger module

0%
Низкий
около 3 лет назад
github логотип
GHSA-phv5-85pf-xrp3

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."

5%
Низкий
около 3 лет назад
github логотип
GHSA-ph8m-2h2f-qgr2

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-ph2j-5hxq-gxrr

Drupal Node Validation Bypass in the node module API

0%
Низкий
около 3 лет назад
github логотип
GHSA-pgxv-w4j7-wh5m

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

1%
Низкий
около 3 лет назад
github логотип
GHSA-pfc2-6vvp-c5mq

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-p8g6-5mg7-9r5q

Drupal REST API can bypass comment approval

CVSS3: 7.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-p745-347h-hjfw

Drupal sensitive information disclosure

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-p6w6-6v99-r2gr

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу