Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

nvd логотип

CVE-2010-2472

почти 6 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2010-2472

почти 6 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2010-2471

почти 6 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2471

почти 6 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2010-2471

почти 6 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2010-2250

почти 6 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2250

почти 6 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2010-2250

почти 6 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2009-4370

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4370

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4370

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/m ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2009-4369

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4369

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4369

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (module ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-3352

почти 16 лет назад

Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-2374

около 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2374

около 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVSS3: 4.8
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
debian логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

CVSS3: 6.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/m ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (module ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-3352

Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

CVSS2: 10
1%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
0%
Низкий
около 16 лет назад

Уязвимостей на страницу