Количество 2 012
Количество 2 012
GHSA-jq73-c7h9-wr72
Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
GHSA-jpj8-49hr-wcwv
Drupal Denial of service via transliterate mechanism
GHSA-jp2q-xrh4-4hph
SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.
GHSA-jmjm-jmgj-gh38
The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
GHSA-jf54-qfqg-9hgv
The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.
GHSA-jf3c-6pm5-6fm9
Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks.
GHSA-jchx-5q5h-f574
** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off."
GHSA-j9pq-x44j-6p86
Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.
GHSA-j586-cj67-vg4p
Cross-Site Request Forgery in Drupal core
GHSA-j47j-5wh7-4gmm
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.
GHSA-j3j6-6mpf-p2c4
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.
GHSA-hxg2-5c8p-ppwm
Drupal has open redirect vulnerability in the Overlay module
GHSA-hw7f-w767-vqpp
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.
GHSA-hqq6-wqq7-jgjq
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.
GHSA-h89p-5896-f4q8
Drupal core allows Content Spoofing
GHSA-h7rp-276p-j58v
Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.
GHSA-h6w3-vjv8-9p4h
Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-h492-8m63-wwhj
Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.
GHSA-h3r9-pjmr-f938
Drupal Brute force amplification attacks via XML-RPC
GHSA-h377-287m-w2r9
Drupal file REST resource does not properly validate
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-jq73-c7h9-wr72 Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack. | 1% Низкий | больше 4 лет назад | ||
GHSA-jpj8-49hr-wcwv Drupal Denial of service via transliterate mechanism | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-jp2q-xrh4-4hph SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment. | 3% Низкий | около 4 лет назад | ||
GHSA-jmjm-jmgj-gh38 The Drupal.checkPlain function in Drupal 6.0 only escapes the first instance of a character in ECMAScript, which allows remote attackers to conduct cross-site scripting (XSS) attacks. | 2% Низкий | около 4 лет назад | ||
GHSA-jf54-qfqg-9hgv The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-jf3c-6pm5-6fm9 Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks. | 2% Низкий | около 4 лет назад | ||
GHSA-jchx-5q5h-f574 ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off." | 4% Низкий | около 4 лет назад | ||
GHSA-j9pq-x44j-6p86 Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files. | 2% Низкий | около 4 лет назад | ||
GHSA-j586-cj67-vg4p Cross-Site Request Forgery in Drupal core | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
GHSA-j47j-5wh7-4gmm Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field. | 1% Низкий | около 4 лет назад | ||
GHSA-j3j6-6mpf-p2c4 Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory. | 11% Средний | около 4 лет назад | ||
GHSA-hxg2-5c8p-ppwm Drupal has open redirect vulnerability in the Overlay module | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-hw7f-w767-vqpp The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use. | 3% Низкий | около 4 лет назад | ||
GHSA-hqq6-wqq7-jgjq Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL. | 2% Низкий | около 4 лет назад | ||
GHSA-h89p-5896-f4q8 Drupal core allows Content Spoofing | 0% Низкий | 8 месяцев назад | ||
GHSA-h7rp-276p-j58v Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users. | 1% Низкий | около 4 лет назад | ||
GHSA-h6w3-vjv8-9p4h Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-h492-8m63-wwhj Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database. | 1% Низкий | около 4 лет назад | ||
GHSA-h3r9-pjmr-f938 Drupal Brute force amplification attacks via XML-RPC | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-h377-287m-w2r9 Drupal file REST resource does not properly validate | CVSS3: 5.9 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу