Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

debian логотип

CVE-2010-2250

больше 5 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4371

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2009-4370

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4370

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4370

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/m ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2009-4369

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4369

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4369

больше 15 лет назад

Cross-site scripting (XSS) vulnerability in the Contact module (module ...

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-3352

почти 16 лет назад

Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-2374

почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2374

почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2374

почти 16 лет назад

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-2373

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2373

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2373

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in the Forum module in Drupal ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-2372

почти 16 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2009-2372

почти 16 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2009-2372

почти 16 лет назад

Drupal 6.x before 6.13 does not prevent users from modifying user sign ...

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/m ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2009-4369

Cross-site scripting (XSS) vulnerability in the Contact module (module ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2009-3352

Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.

CVSS2: 10
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-2374

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize ...

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2009-2373

Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-2373

Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-2373

Cross-site scripting (XSS) vulnerability in the Forum module in Drupal ...

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2009-2372

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

CVSS2: 6.5
1%
Низкий
почти 16 лет назад
nvd логотип
CVE-2009-2372

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

CVSS2: 6.5
1%
Низкий
почти 16 лет назад
debian логотип
CVE-2009-2372

Drupal 6.x before 6.13 does not prevent users from modifying user sign ...

CVSS2: 6.5
1%
Низкий
почти 16 лет назад

Уязвимостей на страницу