Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

debian логотип

CVE-2010-3093

больше 15 лет назад

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-3092

больше 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2010-3092

больше 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2010-3092

больше 15 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2473

около 6 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2010-2473

около 6 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2010-2473

около 6 лет назад

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-2472

около 6 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2010-2472

около 6 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2010-2472

около 6 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2010-2471

около 6 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2471

около 6 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2010-2471

около 6 лет назад

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2010-2250

около 6 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2010-2250

около 6 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2010-2250

около 6 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2009-4371

около 16 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2009-4371

около 16 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2009-4371

около 16 лет назад

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2009-4370

около 16 лет назад

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2010-3093

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allow ...

CVSS2: 3.5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

CVSS2: 5.5
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does n ...

CVSS2: 5.5
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

CVSS3: 6.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2010-2473

Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly b ...

CVSS3: 6.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
1%
Низкий
около 6 лет назад
debian логотип
CVE-2010-2472

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

CVSS3: 4.8
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
около 6 лет назад
debian логотип
CVE-2010-2471

Drupal versions 5.x and 6.x has open redirection

CVSS3: 6.1
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
debian логотип
CVE-2010-2250

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

CVSS3: 6.1
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

CVSS2: 3.5
0%
Низкий
около 16 лет назад
debian логотип
CVE-2009-4371

Cross-site scripting (XSS) vulnerability in the Locale module (modules ...

CVSS2: 3.5
0%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-4370

Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.

CVSS2: 3.5
0%
Низкий
около 16 лет назад

Уязвимостей на страницу