Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

ubuntu логотип

CVE-2010-3094

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2010-3094

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2010-3094

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-3093

почти 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2010-3093

почти 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2010-3093

почти 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3092

почти 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2010-3092

почти 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2010-3092

почти 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2473

больше 5 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2010-2473

больше 5 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2010-2473

больше 5 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2472

больше 5 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2010-2472

больше 5 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2010-2472

больше 5 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2010-2471

больше 5 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2471

больше 5 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2010-2471

больше 5 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2010-2250

больше 5 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2250

больше 5 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVSS2: 5.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу