Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

nvd логотип

CVE-2011-3730

почти 14 лет назад

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-2726

больше 5 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL. This issue affects Drupal 7.x only.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2726

больше 5 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2726

больше 5 лет назад

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-2687

около 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2011-2687

около 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2011-2687

около 14 лет назад

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_ ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3094

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2010-3094

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2010-3094

почти 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-3093

почти 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2010-3093

почти 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2010-3093

почти 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3092

почти 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2010-3092

почти 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2010-3092

почти 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2473

почти 6 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2010-2473

почти 6 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2010-2473

почти 6 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2472

почти 6 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-3730

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and certain other files.

CVSS2: 5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. If a Drupal site is using these features on comments, and the parent node is denied access (either by a node access module or by being unpublished), the file attached to the comment can still be downloaded by non-privileged users if they know or guess its direct URL. This issue affects Drupal 7.x only.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2011-2726

An access bypass issue was found in Drupal 7.x before version 7.5. If ...

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
1%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

CVSS2: 7.5
1%
Низкий
около 14 лет назад
debian логотип
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_ ...

CVSS2: 7.5
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3094

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVSS2: 2.1
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
0%
Низкий
почти 15 лет назад
nvd логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
0%
Низкий
почти 15 лет назад
debian логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVSS2: 5.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVSS3: 6.5
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу