Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 012

Количество 2 012

github логотип

GHSA-pgxv-w4j7-wh5m

около 4 лет назад

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

EPSS: Низкий
github логотип

GHSA-pfc2-6vvp-c5mq

около 4 лет назад

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

EPSS: Низкий
github логотип

GHSA-p8g6-5mg7-9r5q

около 4 лет назад

Drupal REST API can bypass comment approval

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-p745-347h-hjfw

около 4 лет назад

Drupal sensitive information disclosure

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-p6w6-6v99-r2gr

около 4 лет назад

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

EPSS: Низкий
github логотип

GHSA-p68q-6jc7-9w28

около 4 лет назад

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-p4jq-p7qf-pw64

около 4 лет назад

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-p3x4-6c52-8c69

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-mrvq-r8g7-548f

около 4 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

EPSS: Низкий
github логотип

GHSA-mpww-gpm7-w7qg

около 4 лет назад

** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.

EPSS: Низкий
github логотип

GHSA-mmjr-5q74-p3m4

больше 4 лет назад

Exposure of Resource to Wrong Sphere in Drupal Core

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mhpg-hpj5-73r2

8 месяцев назад

Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-mg8j-w93w-xjgc

почти 2 года назад

Drupal Full Path Disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-m6vv-vcj8-w8m7

8 месяцев назад

Drupal core allows Object Injection

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-m6q5-wv4x-fv6h

больше 4 лет назад

Cross-site Scripting in Drupal Core

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m648-hpf8-qcjw

около 4 лет назад

Drupal Core Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-m4wj-hhwj-47qp

больше 1 года назад

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-m4rx-8rj2-qhj2

около 4 лет назад

The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m4pj-47x5-hq8v

около 4 лет назад

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

EPSS: Средний
github логотип

GHSA-m39x-8hp2-rvf4

около 4 лет назад

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pgxv-w4j7-wh5m

Algorithmic complexity vulnerability in the _filter_url function in the text filtering system (modules/filter/filter.module) in Drupal 7.x before 7.14 allows remote authenticated users with certain roles to cause a denial of service (CPU consumption) via a long email address.

1%
Низкий
около 4 лет назад
github логотип
GHSA-pfc2-6vvp-c5mq

Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-p8g6-5mg7-9r5q

Drupal REST API can bypass comment approval

CVSS3: 7.4
2%
Низкий
около 4 лет назад
github логотип
GHSA-p745-347h-hjfw

Drupal sensitive information disclosure

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-p6w6-6v99-r2gr

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to content" via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-p68q-6jc7-9w28

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-p4jq-p7qf-pw64

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-p3x4-6c52-8c69

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mrvq-r8g7-548f

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

2%
Низкий
около 4 лет назад
github логотип
GHSA-mpww-gpm7-w7qg

** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.

1%
Низкий
около 4 лет назад
github логотип
GHSA-mmjr-5q74-p3m4

Exposure of Resource to Wrong Sphere in Drupal Core

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-mhpg-hpj5-73r2

Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels

CVSS3: 3.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-mg8j-w93w-xjgc

Drupal Full Path Disclosure

CVSS3: 5.3
9%
Низкий
почти 2 года назад
github логотип
GHSA-m6vv-vcj8-w8m7

Drupal core allows Object Injection

CVSS3: 5.9
0%
Низкий
8 месяцев назад
github логотип
GHSA-m6q5-wv4x-fv6h

Cross-site Scripting in Drupal Core

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-m648-hpf8-qcjw

Drupal Core Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-m4wj-hhwj-47qp

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-m4rx-8rj2-qhj2

The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-m4pj-47x5-hq8v

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

16%
Средний
около 4 лет назад
github логотип
GHSA-m39x-8hp2-rvf4

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу