Количество 1 966
Количество 1 966

CVE-2010-3094
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

CVE-2010-3094
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.
CVE-2010-3094
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ...

CVE-2010-3093
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.

CVE-2010-3093
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue.
CVE-2010-3093
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVE-2010-3092
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVE-2010-3092
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.
CVE-2010-3092
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
CVE-2010-2473
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
CVE-2010-2472
Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVE-2010-2471
Drupal versions 5.x and 6.x has open redirection

CVE-2010-2471
Drupal versions 5.x and 6.x has open redirection
CVE-2010-2471
Drupal versions 5.x and 6.x has open redirection

CVE-2010-2250
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVE-2010-2250
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2010-3094 Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module. | CVSS2: 2.1 | 0% Низкий | почти 15 лет назад |
![]() | CVE-2010-3094 Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module. | CVSS2: 2.1 | 0% Низкий | почти 15 лет назад |
CVE-2010-3094 Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x befo ... | CVSS2: 2.1 | 0% Низкий | почти 15 лет назад | |
![]() | CVE-2010-3093 The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue. | CVSS2: 3.5 | 0% Низкий | почти 15 лет назад |
![]() | CVE-2010-3093 The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" issue. | CVSS2: 3.5 | 0% Низкий | почти 15 лет назад |
CVE-2010-3093 The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ... | CVSS2: 3.5 | 0% Низкий | почти 15 лет назад | |
![]() | CVE-2010-3092 The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name. | CVSS2: 5.5 | 0% Низкий | почти 15 лет назад |
![]() | CVE-2010-3092 The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name. | CVSS2: 5.5 | 0% Низкий | почти 15 лет назад |
CVE-2010-3092 The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ... | CVSS2: 5.5 | 0% Низкий | почти 15 лет назад | |
![]() | CVE-2010-2473 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | CVSS3: 6.5 | 0% Низкий | больше 5 лет назад |
![]() | CVE-2010-2473 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked. | CVSS3: 6.5 | 0% Низкий | больше 5 лет назад |
CVE-2010-2473 Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ... | CVSS3: 6.5 | 0% Низкий | больше 5 лет назад | |
![]() | CVE-2010-2472 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | CVSS3: 4.8 | 1% Низкий | больше 5 лет назад |
![]() | CVE-2010-2472 Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission. | CVSS3: 4.8 | 1% Низкий | больше 5 лет назад |
CVE-2010-2472 Locale module and dependent contributed modules in Drupal 6.x before 6 ... | CVSS3: 4.8 | 1% Низкий | больше 5 лет назад | |
![]() | CVE-2010-2471 Drupal versions 5.x and 6.x has open redirection | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад |
![]() | CVE-2010-2471 Drupal versions 5.x and 6.x has open redirection | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад |
CVE-2010-2471 Drupal versions 5.x and 6.x has open redirection | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад | |
![]() | CVE-2010-2250 Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад |
![]() | CVE-2010-2250 Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | CVSS3: 6.1 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу