Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

debian логотип

CVE-2012-0827

больше 12 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0826

больше 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0826

больше 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0826

больше 12 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0825

больше 12 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0825

больше 12 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0825

больше 12 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-3730

больше 14 лет назад

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-3730

больше 14 лет назад

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-2726

около 6 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL. This issue affects Drupal 7.x only.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2726

около 6 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2726

около 6 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-2687

больше 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2687

больше 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2687

больше 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_ ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3094

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2010-3094

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2010-3094

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-3093

больше 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2010-3093

больше 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified fiel ...

CVSS2: 3.5
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator modu ...

CVSS2: 6.8
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attrib ...

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL. This issue affects Drupal 7.x only.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_ ...

CVSS2: 7.5
1%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 2.1
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад

Уязвимостей на страницу