Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-p68q-6jc7-9w28

около 3 лет назад

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-p4jq-p7qf-pw64

около 3 лет назад

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-p3x4-6c52-8c69

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-mrvq-r8g7-548f

около 3 лет назад

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

EPSS: Низкий
github логотип

GHSA-mpww-gpm7-w7qg

около 3 лет назад

** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.

EPSS: Низкий
github логотип

GHSA-mmjr-5q74-p3m4

больше 3 лет назад

Exposure of Resource to Wrong Sphere in Drupal Core

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mg8j-w93w-xjgc

10 месяцев назад

Drupal Full Path Disclosure

CVSS3: 5.3
EPSS: Высокий
github логотип

GHSA-m6q5-wv4x-fv6h

больше 3 лет назад

Cross-site Scripting in Drupal Core

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-m648-hpf8-qcjw

около 3 лет назад

Drupal Core Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-m4wj-hhwj-47qp

3 месяца назад

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-m4rx-8rj2-qhj2

около 3 лет назад

The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m4pj-47x5-hq8v

около 3 лет назад

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

EPSS: Средний
github логотип

GHSA-m39x-8hp2-rvf4

около 3 лет назад

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

EPSS: Низкий
github логотип

GHSA-jq73-c7h9-wr72

около 3 лет назад

Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

EPSS: Низкий
github логотип

GHSA-jpj8-49hr-wcwv

около 3 лет назад

Drupal Denial of service via transliterate mechanism

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jp2q-xrh4-4hph

около 3 лет назад

SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

EPSS: Средний
github логотип

GHSA-jmjm-jmgj-gh38

около 3 лет назад

The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

EPSS: Низкий
github логотип

GHSA-jf54-qfqg-9hgv

около 3 лет назад

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-jf3c-6pm5-6fm9

около 3 лет назад

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

EPSS: Низкий
github логотип

GHSA-jchx-5q5h-f574

около 3 лет назад

** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p68q-6jc7-9w28

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

5%
Низкий
около 3 лет назад
github логотип
GHSA-p4jq-p7qf-pw64

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-p3x4-6c52-8c69

Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-mrvq-r8g7-548f

The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading .html files.

1%
Низкий
около 3 лет назад
github логотип
GHSA-mpww-gpm7-w7qg

** DISPUTED ** Drupal allows remote attackers to conduct cross-site scripting (XSS) attacks via an IMG tag with an unusual encoded Javascript function name, as demonstrated using variations of the alert() function. NOTE: a followup by the vendor suggests that the issue does not exist in 4.5.6 or 4.6.4 when "Filtered HTML" is enabled, and since "Full HTML" would not filter HTML by design, perhaps this should not be included in CVE.

0%
Низкий
около 3 лет назад
github логотип
GHSA-mmjr-5q74-p3m4

Exposure of Resource to Wrong Sphere in Drupal Core

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mg8j-w93w-xjgc

Drupal Full Path Disclosure

CVSS3: 5.3
80%
Высокий
10 месяцев назад
github логотип
GHSA-m6q5-wv4x-fv6h

Cross-site Scripting in Drupal Core

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-m648-hpf8-qcjw

Drupal Core Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-m4wj-hhwj-47qp

Drupal Core Cross-Site Scripting (XSS) Vulnerability

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-m4rx-8rj2-qhj2

The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-m4pj-47x5-hq8v

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

56%
Средний
около 3 лет назад
github логотип
GHSA-m39x-8hp2-rvf4

The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

1%
Низкий
около 3 лет назад
github логотип
GHSA-jq73-c7h9-wr72

Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

1%
Низкий
около 3 лет назад
github логотип
GHSA-jpj8-49hr-wcwv

Drupal Denial of service via transliterate mechanism

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-jp2q-xrh4-4hph

SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.

14%
Средний
около 3 лет назад
github логотип
GHSA-jmjm-jmgj-gh38

The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

0%
Низкий
около 3 лет назад
github логотип
GHSA-jf54-qfqg-9hgv

The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

1%
Низкий
около 3 лет назад
github логотип
GHSA-jf3c-6pm5-6fm9

Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.

1%
Низкий
около 3 лет назад
github логотип
GHSA-jchx-5q5h-f574

** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off."

2%
Низкий
около 3 лет назад

Уязвимостей на страницу