Количество 1 975
Количество 1 975

CVE-2014-9015
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
CVE-2014-9015
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ...

CVE-2014-5267
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

CVE-2014-5267
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
CVE-2014-5267
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 ...

CVE-2014-5022
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVE-2014-5022
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.
CVE-2014-5022
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal ...

CVE-2014-5021
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVE-2014-5021
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
CVE-2014-5021
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x ...

CVE-2014-5020
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVE-2014-5020
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
CVE-2014-5020
The File module in Drupal 7.x before 7.29 does not properly check perm ...

CVE-2014-5019
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVE-2014-5019
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.
CVE-2014-5019
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 al ...

CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.
CVE-2014-3704
The expandArguments function in the database abstraction API in Drupal ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2014-9015 Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions. | CVSS2: 6.8 | 1% Низкий | больше 10 лет назад |
CVE-2014-9015 Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to ... | CVSS2: 6.8 | 1% Низкий | больше 10 лет назад | |
![]() | CVE-2014-5267 modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document. | CVSS2: 6.8 | 1% Низкий | почти 11 лет назад |
![]() | CVE-2014-5267 modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document. | CVSS2: 6.8 | 1% Низкий | почти 11 лет назад |
CVE-2014-5267 modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 ... | CVSS2: 6.8 | 1% Низкий | почти 11 лет назад | |
![]() | CVE-2014-5022 Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field. | CVSS2: 4.3 | 0% Низкий | около 11 лет назад |
![]() | CVE-2014-5022 Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field. | CVSS2: 4.3 | 0% Низкий | около 11 лет назад |
CVE-2014-5022 Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal ... | CVSS2: 4.3 | 0% Низкий | около 11 лет назад | |
![]() | CVE-2014-5021 Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label. | CVSS2: 2.1 | 0% Низкий | около 11 лет назад |
![]() | CVE-2014-5021 Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label. | CVSS2: 2.1 | 0% Низкий | около 11 лет назад |
CVE-2014-5021 Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x ... | CVSS2: 2.1 | 0% Низкий | около 11 лет назад | |
![]() | CVE-2014-5020 The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. | CVSS2: 4.9 | 0% Низкий | около 11 лет назад |
![]() | CVE-2014-5020 The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field. | CVSS2: 4.9 | 0% Низкий | около 11 лет назад |
CVE-2014-5020 The File module in Drupal 7.x before 7.29 does not properly check perm ... | CVSS2: 4.9 | 0% Низкий | около 11 лет назад | |
![]() | CVE-2014-5019 The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use. | CVSS2: 5 | 0% Низкий | около 11 лет назад |
![]() | CVE-2014-5019 The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use. | CVSS2: 5 | 0% Низкий | около 11 лет назад |
CVE-2014-5019 The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 al ... | CVSS2: 5 | 0% Низкий | около 11 лет назад | |
![]() | CVE-2014-3704 The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | CVSS2: 7.5 | 94% Критический | почти 11 лет назад |
![]() | CVE-2014-3704 The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys. | CVSS2: 7.5 | 94% Критический | почти 11 лет назад |
CVE-2014-3704 The expandArguments function in the database abstraction API in Drupal ... | CVSS2: 7.5 | 94% Критический | почти 11 лет назад |
Уязвимостей на страницу