Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 966

Количество 1 966

github логотип

GHSA-j9pq-x44j-6p86

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.

EPSS: Низкий
github логотип

GHSA-j586-cj67-vg4p

больше 3 лет назад

Cross-Site Request Forgery in Drupal core

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j47j-5wh7-4gmm

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

EPSS: Низкий
github логотип

GHSA-j3j6-6mpf-p2c4

около 3 лет назад

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

EPSS: Средний
github логотип

GHSA-hxg2-5c8p-ppwm

около 3 лет назад

Drupal has open redirect vulnerability in the Overlay module

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hw7f-w767-vqpp

около 3 лет назад

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

EPSS: Низкий
github логотип

GHSA-hqq6-wqq7-jgjq

около 3 лет назад

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

EPSS: Низкий
github логотип

GHSA-h7rp-276p-j58v

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.

EPSS: Низкий
github логотип

GHSA-h6w3-vjv8-9p4h

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-h492-8m63-wwhj

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

EPSS: Низкий
github логотип

GHSA-h3r9-pjmr-f938

около 3 лет назад

Drupal Brute force amplification attacks via XML-RPC

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h377-287m-w2r9

около 3 лет назад

Drupal file REST resource does not properly validate

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-gxxq-fhc7-3jv9

около 3 лет назад

Drupal Cross-Site Request Forgery (CSRF)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gx79-7p8q-959r

около 3 лет назад

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

EPSS: Низкий
github логотип

GHSA-gvf2-2f4g-jqf4

6 месяцев назад

Drupal core contains a potential PHP Object Injection vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gjqg-9rhv-qj67

около 3 лет назад

Drupal Core Open Redirect vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-gfh7-vc32-58w3

около 3 лет назад

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-g8mw-h5hw-6g35

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

EPSS: Низкий
github логотип

GHSA-g749-r93q-q2rq

около 3 лет назад

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

EPSS: Низкий
github логотип

GHSA-g36h-4jr6-qmm9

около 2 лет назад

Improper input validation in Drupal core

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j9pq-x44j-6p86

Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.

1%
Низкий
около 3 лет назад
github логотип
GHSA-j586-cj67-vg4p

Cross-Site Request Forgery in Drupal core

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-j47j-5wh7-4gmm

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

0%
Низкий
около 3 лет назад
github логотип
GHSA-j3j6-6mpf-p2c4

Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

20%
Средний
около 3 лет назад
github логотип
GHSA-hxg2-5c8p-ppwm

Drupal has open redirect vulnerability in the Overlay module

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-hw7f-w767-vqpp

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

0%
Низкий
около 3 лет назад
github логотип
GHSA-hqq6-wqq7-jgjq

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

0%
Низкий
около 3 лет назад
github логотип
GHSA-h7rp-276p-j58v

Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.

0%
Низкий
около 3 лет назад
github логотип
GHSA-h6w3-vjv8-9p4h

Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
около 3 лет назад
github логотип
GHSA-h492-8m63-wwhj

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

0%
Низкий
около 3 лет назад
github логотип
GHSA-h3r9-pjmr-f938

Drupal Brute force amplification attacks via XML-RPC

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-h377-287m-w2r9

Drupal file REST resource does not properly validate

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-gxxq-fhc7-3jv9

Drupal Cross-Site Request Forgery (CSRF)

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-gx79-7p8q-959r

SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."

1%
Низкий
около 3 лет назад
github логотип
GHSA-gvf2-2f4g-jqf4

Drupal core contains a potential PHP Object Injection vulnerability

CVSS3: 9.8
3%
Низкий
6 месяцев назад
github логотип
GHSA-gjqg-9rhv-qj67

Drupal Core Open Redirect vulnerability

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-gfh7-vc32-58w3

CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

2%
Низкий
около 3 лет назад
github логотип
GHSA-g8mw-h5hw-6g35

Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."

0%
Низкий
около 3 лет назад
github логотип
GHSA-g749-r93q-q2rq

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a file by uploading a different file with a similar name.

0%
Низкий
около 3 лет назад
github логотип
GHSA-g36h-4jr6-qmm9

Improper input validation in Drupal core

CVSS3: 7.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу