Количество 1 975
Количество 1 975
CVE-2012-1591
The image module in Drupal 7.x before 7.14 does not properly check per ...

CVE-2012-1590
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.

CVE-2012-1590
The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page.
CVE-2012-1590
The forum list in Drupal 7.x before 7.14 does not properly check user ...

CVE-2012-1589
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.

CVE-2012-1589
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
CVE-2012-1589
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 ...

CVE-2012-1588
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

CVE-2012-1588
Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.
CVE-2012-1588
Algorithmic complexity vulnerability in the _filter_url function in th ...

CVE-2012-0827
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVE-2012-0827
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.
CVE-2012-0827
The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVE-2012-0826
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVE-2012-0826
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.
CVE-2012-0826
Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVE-2012-0825
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVE-2012-0825
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
CVE-2012-0825
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVE-2011-3730
Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2012-1591 The image module in Drupal 7.x before 7.14 does not properly check per ... | CVSS2: 5 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-1590 The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
![]() | CVE-2012-1590 The forum list in Drupal 7.x before 7.14 does not properly check user permissions for unpublished forum posts, which allows remote authenticated users to obtain sensitive information such as the post title via the forum overview page. | CVSS2: 4 | 0% Низкий | почти 13 лет назад |
CVE-2012-1590 The forum list in Drupal 7.x before 7.14 does not properly check user ... | CVSS2: 4 | 0% Низкий | почти 13 лет назад | |
![]() | CVE-2012-1589 Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL. | CVSS2: 5.8 | 0% Низкий | около 13 лет назад |
![]() | CVE-2012-1589 Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL. | CVSS2: 5.8 | 0% Низкий | около 13 лет назад |
CVE-2012-1589 Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 ... | CVSS2: 5.8 | 0% Низкий | около 13 лет назад | |
![]() | CVE-2012-1588 Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address. | CVSS2: 3.5 | 1% Низкий | почти 13 лет назад |
![]() | CVE-2012-1588 Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address. | CVSS2: 3.5 | 1% Низкий | почти 13 лет назад |
CVE-2012-1588 Algorithmic complexity vulnerability in the _filter_url function in th ... | CVSS2: 3.5 | 1% Низкий | почти 13 лет назад | |
![]() | CVE-2012-0827 The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors. | CVSS2: 3.5 | 0% Низкий | почти 12 лет назад |
![]() | CVE-2012-0827 The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors. | CVSS2: 3.5 | 0% Низкий | почти 12 лет назад |
CVE-2012-0827 The File module in Drupal 7.x before 7.11, when using unspecified fiel ... | CVSS2: 3.5 | 0% Низкий | почти 12 лет назад | |
![]() | CVE-2012-0826 Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors. | CVSS2: 6.8 | 0% Низкий | почти 12 лет назад |
![]() | CVE-2012-0826 Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors. | CVSS2: 6.8 | 0% Низкий | почти 12 лет назад |
CVE-2012-0826 Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ... | CVSS2: 6.8 | 0% Низкий | почти 12 лет назад | |
![]() | CVE-2012-0825 Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack. | CVSS2: 6.8 | 0% Низкий | почти 12 лет назад |
![]() | CVE-2012-0825 Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack. | CVSS2: 6.8 | 0% Низкий | почти 12 лет назад |
CVE-2012-0825 Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ... | CVSS2: 6.8 | 0% Низкий | почти 12 лет назад | |
![]() | CVE-2011-3730 Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files. | CVSS2: 5 | 1% Низкий | почти 14 лет назад |
Уязвимостей на страницу