Количество 2 012
Количество 2 012
GHSA-rjjm-xf3c-gmh6
The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors.
GHSA-rhx9-3qf7-r3j7
Drupal Remote code execution
GHSA-rfxx-gxwc-923c
Drupal Views can allow unauthorized users to see Statistics information
GHSA-rcwp-vp94-qpq4
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.
GHSA-qvqj-pfj9-vcvw
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
GHSA-qrwq-jwq3-8cc8
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
GHSA-qr75-jf52-qrw8
** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.
GHSA-qqxc-cppg-4xp8
Drupal Reflected file download vulnerability
GHSA-qfhg-m6r8-xxpj
Incorrect Authorization in Drupal core
GHSA-qf2g-mrrx-rr5p
Drupal Core Cross-site scripting vulnerability
GHSA-q4hh-4qxq-c529
Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
GHSA-q3p9-8728-wq7x
Drupal saving user accounts can sometimes grant the user all roles
GHSA-pw6f-3999-xp7g
Drupal core allows Cross-Site Scripting (XSS)
GHSA-pw4m-g5pv-hrp6
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.
GHSA-pqv4-xgqh-j8vh
Drupal sensitive information disclosure
GHSA-pp4m-6679-4g83
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.
GHSA-pjmx-4gc6-hwv8
Drupal cross-site scripting vulnerability via actions feature and trigger module
GHSA-phv5-85pf-xrp3
The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."
GHSA-ph8m-2h2f-qgr2
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
GHSA-ph2j-5hxq-gxrr
Drupal Node Validation Bypass in the node module API
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-rjjm-xf3c-gmh6 The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-rhx9-3qf7-r3j7 Drupal Remote code execution | CVSS3: 8.1 | 4% Низкий | около 4 лет назад | |
GHSA-rfxx-gxwc-923c Drupal Views can allow unauthorized users to see Statistics information | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-rcwp-vp94-qpq4 The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers. | 2% Низкий | около 4 лет назад | ||
GHSA-qvqj-pfj9-vcvw Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. | 3% Низкий | около 4 лет назад | ||
GHSA-qrwq-jwq3-8cc8 Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. | CVSS3: 3.1 | 0% Низкий | 20 дней назад | |
GHSA-qr75-jf52-qrw8 ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future. | 1% Низкий | около 4 лет назад | ||
GHSA-qqxc-cppg-4xp8 Drupal Reflected file download vulnerability | CVSS3: 6.4 | 2% Низкий | около 4 лет назад | |
GHSA-qfhg-m6r8-xxpj Incorrect Authorization in Drupal core | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-qf2g-mrrx-rr5p Drupal Core Cross-site scripting vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-q4hh-4qxq-c529 Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 3% Низкий | около 4 лет назад | ||
GHSA-q3p9-8728-wq7x Drupal saving user accounts can sometimes grant the user all roles | CVSS3: 8.1 | 2% Низкий | около 4 лет назад | |
GHSA-pw6f-3999-xp7g Drupal core allows Cross-Site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
GHSA-pw4m-g5pv-hrp6 Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL. | 1% Низкий | около 4 лет назад | ||
GHSA-pqv4-xgqh-j8vh Drupal sensitive information disclosure | CVSS3: 5.3 | 2% Низкий | около 4 лет назад | |
GHSA-pp4m-6679-4g83 The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | 1% Низкий | около 4 лет назад | ||
GHSA-pjmx-4gc6-hwv8 Drupal cross-site scripting vulnerability via actions feature and trigger module | 1% Низкий | около 4 лет назад | ||
GHSA-phv5-85pf-xrp3 The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines." | 3% Низкий | около 4 лет назад | ||
GHSA-ph8m-2h2f-qgr2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-ph2j-5hxq-gxrr Drupal Node Validation Bypass in the node module API | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу