Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

ubuntu логотип

CVE-2012-1588

больше 12 лет назад

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-1588

больше 12 лет назад

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-1588

больше 12 лет назад

Algorithmic complexity vulnerability in the _filter_url function in th ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0827

больше 11 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-0827

больше 11 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-0827

больше 11 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0826

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0826

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0826

больше 11 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0825

больше 11 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0825

больше 11 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0825

больше 11 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-3730

почти 14 лет назад

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3730

почти 14 лет назад

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-2726

больше 5 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2726

больше 5 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2726

больше 5 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-2687

почти 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2687

почти 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2687

почти 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_ ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-1588

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVSS2: 3.5
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-1588

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVSS2: 3.5
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-1588

Algorithmic complexity vulnerability in the _filter_url function in th ...

CVSS2: 3.5
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVSS2: 3.5
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVSS2: 6.8
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_ ...

CVSS2: 7.5
1%
Низкий
почти 14 лет назад

Уязвимостей на страницу