Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

ubuntu логотип

CVE-2015-3231

около 10 лет назад

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2015-3231

около 10 лет назад

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2015-3231

около 10 лет назад

The Render cache system in Drupal 7.x before 7.38, when used to cache ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-2750

почти 8 лет назад

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-2750

почти 8 лет назад

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-2750

почти 8 лет назад

Open redirect vulnerability in URL-related API functions in Drupal 6.x ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-2749

почти 8 лет назад

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2015-2749

почти 8 лет назад

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2015-2749

почти 8 лет назад

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7 ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-2559

около 10 лет назад

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2015-2559

около 10 лет назад

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2015-2559

около 10 лет назад

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9015

больше 10 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-9015

больше 10 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-9015

больше 10 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5267

больше 10 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-5267

больше 10 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-5267

больше 10 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5022

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-5022

почти 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-3231

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

CVSS2: 4
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-3231

The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.

CVSS2: 4
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-3231

The Render cache system in Drupal 7.x before 7.38, when used to cache ...

CVSS2: 4
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-2750

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2015-2750

Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2015-2750

Open redirect vulnerability in URL-related API functions in Drupal 6.x ...

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2015-2749

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2015-2749

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
debian логотип
CVE-2015-2749

Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7 ...

CVSS3: 6.1
1%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2015-2559

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-2559

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

CVSS2: 3.5
0%
Низкий
около 10 лет назад
debian логотип
CVE-2015-2559

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated ...

CVSS2: 3.5
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVSS2: 6.8
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад

Уязвимостей на страницу