Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 988

Количество 1 988

ubuntu логотип

CVE-2006-2833

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-2833

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-2833

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the taxonomy module in Dru ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-2832

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-2832

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-2832

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the upload module (upload. ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-2831

больше 19 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-2831

больше 19 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-2831

больше 19 лет назад

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under c ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-2743

больше 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2006-2743

больше 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

CVSS2: 5.1
EPSS: Средний
debian логотип

CVE-2006-2743

больше 19 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_m ...

CVSS2: 5.1
EPSS: Средний
ubuntu логотип

CVE-2006-2742

больше 19 лет назад

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-2742

больше 19 лет назад

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-2742

больше 19 лет назад

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 all ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-2260

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-2260

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2260

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the project module (projec ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-1228

почти 20 лет назад

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-1228

почти 20 лет назад

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2006-2833

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

CVSS2: 2.6
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2833

Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $names variable.

CVSS2: 2.6
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2833

Cross-site scripting (XSS) vulnerability in the taxonomy module in Dru ...

CVSS2: 2.6
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2832

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

CVSS2: 2.6
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2832

Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.

CVSS2: 2.6
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2832

Cross-site scripting (XSS) vulnerability in the upload module (upload. ...

CVSS2: 2.6
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2831

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

CVSS2: 7.5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2831

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled within .htaccess, allows remote attackers to execute arbitrary code by uploading a file with multiple extensions, a variant of CVE-2006-2743.

CVSS2: 7.5
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2831

Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under c ...

CVSS2: 7.5
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2743

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

CVSS2: 5.1
23%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-2743

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

CVSS2: 5.1
23%
Средний
больше 19 лет назад
debian логотип
CVE-2006-2743

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_m ...

CVSS2: 5.1
23%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2006-2742

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2742

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2) from variables to (a) database.mysql.inc, (b) database.pgsql.inc, and (c) database.mysqli.inc.

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2742

SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 all ...

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2260

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
0%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2260

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
0%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2260

Cross-site scripting (XSS) vulnerability in the project module (projec ...

CVSS2: 4.3
0%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

CVSS2: 5.1
2%
Низкий
почти 20 лет назад
nvd логотип
CVE-2006-1228

Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

CVSS2: 5.1
2%
Низкий
почти 20 лет назад

Уязвимостей на страницу