Количество 1 966
Количество 1 966
GHSA-rcwp-vp94-qpq4
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.
GHSA-qvqj-pfj9-vcvw
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
GHSA-qr75-jf52-qrw8
** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future.
GHSA-qqxc-cppg-4xp8
Drupal Reflected file download vulnerability
GHSA-qfhg-m6r8-xxpj
Incorrect Authorization in Drupal core
GHSA-qf2g-mrrx-rr5p
Drupal Core Cross-site scripting vulnerability
GHSA-q4hh-4qxq-c529
Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
GHSA-q3p9-8728-wq7x
Drupal saving user accounts can sometimes grant the user all roles
GHSA-pw4m-g5pv-hrp6
Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL.
GHSA-pqv4-xgqh-j8vh
Drupal sensitive information disclosure
GHSA-pp4m-6679-4g83
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.
GHSA-pjmx-4gc6-hwv8
Drupal cross-site scripting vulnerability via actions feature and trigger module
GHSA-phv5-85pf-xrp3
The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."
GHSA-ph8m-2h2f-qgr2
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
GHSA-ph2j-5hxq-gxrr
Drupal Node Validation Bypass in the node module API
GHSA-pgxv-w4j7-wh5m
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.
GHSA-pfc2-6vvp-c5mq
Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.
GHSA-p8g6-5mg7-9r5q
Drupal REST API can bypass comment approval
GHSA-p745-347h-hjfw
Drupal sensitive information disclosure
GHSA-p6w6-6v99-r2gr
The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-rcwp-vp94-qpq4 The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers. | 0% Низкий | около 3 лет назад | ||
GHSA-qvqj-pfj9-vcvw Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. | 1% Низкий | около 3 лет назад | ||
GHSA-qr75-jf52-qrw8 ** DISPUTED ** Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future. | 0% Низкий | около 3 лет назад | ||
GHSA-qqxc-cppg-4xp8 Drupal Reflected file download vulnerability | CVSS3: 6.4 | 1% Низкий | около 3 лет назад | |
GHSA-qfhg-m6r8-xxpj Incorrect Authorization in Drupal core | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-qf2g-mrrx-rr5p Drupal Core Cross-site scripting vulnerability | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-q4hh-4qxq-c529 Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 2% Низкий | около 3 лет назад | ||
GHSA-q3p9-8728-wq7x Drupal saving user accounts can sometimes grant the user all roles | CVSS3: 8.1 | 1% Низкий | около 3 лет назад | |
GHSA-pw4m-g5pv-hrp6 Drupal 4.6.x before 4.6.10 and 4.7.x before 4.7.4 allows form submissions to be redirected, which allows remote attackers to obtain arbitrary form information via a crafted URL. | 1% Низкий | около 3 лет назад | ||
GHSA-pqv4-xgqh-j8vh Drupal sensitive information disclosure | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-pp4m-6679-4g83 The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | 0% Низкий | около 3 лет назад | ||
GHSA-pjmx-4gc6-hwv8 Drupal cross-site scripting vulnerability via actions feature and trigger module | 0% Низкий | около 3 лет назад | ||
GHSA-phv5-85pf-xrp3 The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines." | 5% Низкий | около 3 лет назад | ||
GHSA-ph8m-2h2f-qgr2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-ph2j-5hxq-gxrr Drupal Node Validation Bypass in the node module API | 0% Низкий | около 3 лет назад | ||
GHSA-pgxv-w4j7-wh5m Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address. | 1% Низкий | около 3 лет назад | ||
GHSA-pfc2-6vvp-c5mq Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter. | 0% Низкий | около 3 лет назад | ||
GHSA-p8g6-5mg7-9r5q Drupal REST API can bypass comment approval | CVSS3: 7.4 | 0% Низкий | около 3 лет назад | |
GHSA-p745-347h-hjfw Drupal sensitive information disclosure | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-p6w6-6v99-r2gr The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors. | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу