Количество 1 975
Количество 1 975

CVE-2008-3661
Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVE-2008-3661
Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVE-2008-3661
Drupal, probably 5.10 and 6.4, does not set the secure flag for the se ...

CVE-2008-3223
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVE-2008-3223
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
CVE-2008-3223
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 ...

CVE-2008-3222
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVE-2008-3222
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
CVE-2008-3222
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVE-2008-3221
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVE-2008-3221
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
CVE-2008-3221
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6 ...

CVE-2008-3220
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVE-2008-3220
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
CVE-2008-3220
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5 ...

CVE-2008-3219
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

CVE-2008-3219
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
CVE-2008-3219
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before ...

CVE-2008-3218
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.

CVE-2008-3218
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2008-3661 Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 1% Низкий | около 17 лет назад | |
![]() | CVE-2008-3661 Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | CVSS2: 5 | 1% Низкий | почти 17 лет назад |
CVE-2008-3661 Drupal, probably 5.10 and 6.4, does not set the secure flag for the se ... | CVSS2: 5 | 1% Низкий | почти 17 лет назад | |
![]() | CVE-2008-3223 SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields." | CVSS2: 7.5 | 1% Низкий | около 17 лет назад |
![]() | CVE-2008-3223 SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields." | CVSS2: 7.5 | 1% Низкий | около 17 лет назад |
CVE-2008-3223 SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 ... | CVSS2: 7.5 | 1% Низкий | около 17 лет назад | |
![]() | CVE-2008-3222 Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. | CVSS2: 5.8 | 1% Низкий | около 17 лет назад |
![]() | CVE-2008-3222 Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. | CVSS2: 5.8 | 1% Низкий | около 17 лет назад |
CVE-2008-3222 Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ... | CVSS2: 5.8 | 1% Низкий | около 17 лет назад | |
![]() | CVE-2008-3221 Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities. | CVSS2: 4.3 | 0% Низкий | около 17 лет назад |
![]() | CVE-2008-3221 Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities. | CVSS2: 4.3 | 0% Низкий | около 17 лет назад |
CVE-2008-3221 Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6 ... | CVSS2: 4.3 | 0% Низкий | около 17 лет назад | |
![]() | CVE-2008-3220 Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | CVSS2: 4.3 | 0% Низкий | около 17 лет назад |
![]() | CVE-2008-3220 Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings." | CVSS2: 4.3 | 0% Низкий | около 17 лет назад |
CVE-2008-3220 Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5 ... | CVSS2: 4.3 | 0% Низкий | около 17 лет назад | |
![]() | CVE-2008-3219 The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism. | CVSS2: 4.3 | 1% Низкий | около 17 лет назад |
![]() | CVE-2008-3219 The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism. | CVSS2: 4.3 | 1% Низкий | около 17 лет назад |
CVE-2008-3219 The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before ... | CVSS2: 4.3 | 1% Низкий | около 17 лет назад | |
![]() | CVE-2008-3218 Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values. | CVSS2: 4.3 | 0% Низкий | около 17 лет назад |
![]() | CVE-2008-3218 Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values. | CVSS2: 4.3 | 0% Низкий | около 17 лет назад |
Уязвимостей на страницу