Количество 2 029
Количество 2 029
CVE-2013-0244
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.
CVE-2013-0244
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.
CVE-2013-0244
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and ...
CVE-2012-5653
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
CVE-2012-5653
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.
CVE-2012-5653
The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 ...
CVE-2012-5652
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
CVE-2012-5652
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.
CVE-2012-5652
Drupal 6.x before 6.27 allows remote attackers to obtain sensitive inf ...
CVE-2012-5651
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
CVE-2012-5651
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.
CVE-2012-5651
Drupal 6.x before 6.27 and 7.x before 7.18 displays information for bl ...
CVE-2012-4554
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.
CVE-2012-4554
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.
CVE-2012-4554
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID serve ...
CVE-2012-4553
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."
CVE-2012-4553
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions."
CVE-2012-4553
Drupal 7.x before 7.16 allows remote attackers to obtain sensitive inf ...
CVE-2012-2922
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
CVE-2012-2922
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2013-0244 Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements. | CVSS2: 2.6 | 2% Низкий | больше 12 лет назад | |
CVE-2013-0244 Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements. | CVSS2: 2.6 | 2% Низкий | больше 12 лет назад | |
CVE-2013-0244 Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and ... | CVSS2: 2.6 | 2% Низкий | больше 12 лет назад | |
CVE-2012-5653 The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name. | CVSS2: 6 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5653 The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name. | CVSS2: 6 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5653 The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 ... | CVSS2: 6 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5652 Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. | CVSS2: 5 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5652 Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result. | CVSS2: 5 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5652 Drupal 6.x before 6.27 allows remote attackers to obtain sensitive inf ... | CVSS2: 5 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5651 Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results. | CVSS2: 5 | 3% Низкий | больше 13 лет назад | |
CVE-2012-5651 Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results. | CVSS2: 5 | 3% Низкий | больше 13 лет назад | |
CVE-2012-5651 Drupal 6.x before 6.27 and 7.x before 7.18 displays information for bl ... | CVSS2: 5 | 3% Низкий | больше 13 лет назад | |
CVE-2012-4554 The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file. | CVSS2: 5 | 16% Средний | больше 13 лет назад | |
CVE-2012-4554 The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file. | CVSS2: 5 | 16% Средний | больше 13 лет назад | |
CVE-2012-4554 The OpenID module in Drupal 7.x before 7.16 allows remote OpenID serve ... | CVSS2: 5 | 16% Средний | больше 13 лет назад | |
CVE-2012-4553 Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions." | CVSS2: 6.8 | 2% Низкий | больше 13 лет назад | |
CVE-2012-4553 Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an external database server, related to "transient conditions." | CVSS2: 6.8 | 2% Низкий | больше 13 лет назад | |
CVE-2012-4553 Drupal 7.x before 7.16 allows remote attackers to obtain sensitive inf ... | CVSS2: 6.8 | 2% Низкий | больше 13 лет назад | |
CVE-2012-2922 The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message. | CVSS2: 5 | 3% Низкий | около 14 лет назад | |
CVE-2012-2922 The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message. | CVSS2: 5 | 3% Низкий | около 14 лет назад |
Уязвимостей на страницу