Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

nvd логотип

CVE-2014-9015

больше 10 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-9015

больше 10 лет назад

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5267

почти 11 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-5267

почти 11 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-5267

почти 11 лет назад

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5022

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-5022

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-5022

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-5021

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2014-5021

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2014-5021

около 11 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-5020

около 11 лет назад

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2014-5020

около 11 лет назад

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2014-5020

около 11 лет назад

The File module in Drupal 7.x before 7.29 does not properly check perm ...

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2014-5019

около 11 лет назад

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-5019

около 11 лет назад

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-5019

около 11 лет назад

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 al ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-3704

почти 11 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
EPSS: Критический
nvd логотип

CVE-2014-3704

почти 11 лет назад

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
EPSS: Критический
debian логотип

CVE-2014-3704

почти 11 лет назад

The expandArguments function in the database abstraction API in Drupal ...

CVSS2: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVSS2: 6.8
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 ...

CVSS2: 6.8
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal ...

CVSS2: 4.3
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-5021

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVSS2: 2.1
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-5021

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVSS2: 2.1
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-5021

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x ...

CVSS2: 2.1
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-5020

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVSS2: 4.9
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-5020

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVSS2: 4.9
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-5020

The File module in Drupal 7.x before 7.29 does not properly check perm ...

CVSS2: 4.9
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVSS2: 5
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVSS2: 5
0%
Низкий
около 11 лет назад
debian логотип
CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 al ...

CVSS2: 5
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
94%
Критический
почти 11 лет назад
nvd логотип
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVSS2: 7.5
94%
Критический
почти 11 лет назад
debian логотип
CVE-2014-3704

The expandArguments function in the database abstraction API in Drupal ...

CVSS2: 7.5
94%
Критический
почти 11 лет назад

Уязвимостей на страницу