Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 029

Количество 2 029

nvd логотип

CVE-2008-3741

почти 18 лет назад

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2008-3741

почти 18 лет назад

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 tr ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2008-3740

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3740

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3740

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in the output filter in Drupa ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3661

почти 18 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2008-3661

почти 18 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

EPSS: Низкий
nvd логотип

CVE-2008-3661

почти 18 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-3661

почти 18 лет назад

Drupal, probably 5.10 and 6.4, does not set the secure flag for the se ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-3223

около 18 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3223

около 18 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-3223

около 18 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-3222

около 18 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2008-3222

около 18 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2008-3222

около 18 лет назад

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2008-3221

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3221

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3221

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3220

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3220

около 18 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-3741

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

CVSS2: 3.5
1%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3741

The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 tr ...

CVSS2: 3.5
1%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3740

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-3740

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3740

Cross-site scripting (XSS) vulnerability in the output filter in Drupa ...

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVSS2: 5
3%
Низкий
почти 18 лет назад
redhat логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

CVSS2: 5
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3661

Drupal, probably 5.10 and 6.4, does not set the secure flag for the se ...

CVSS2: 5
3%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

CVSS2: 7.5
3%
Низкий
около 18 лет назад
debian логотип
CVE-2008-3223

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 ...

CVSS2: 7.5
3%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVSS2: 5.8
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.

CVSS2: 5.8
3%
Низкий
около 18 лет назад
debian логотип
CVE-2008-3222

Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before ...

CVSS2: 5.8
3%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-3221

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3221

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.

CVSS2: 4.3
1%
Низкий
около 18 лет назад
debian логотип
CVE-2008-3221

Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6 ...

CVSS2: 4.3
1%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-3220

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
1%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3220

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

CVSS2: 4.3
1%
Низкий
около 18 лет назад

Уязвимостей на страницу