Логотип exploitDog
product: "drupal"
Консоль
Логотип exploitDog

exploitDog

product: "drupal"

Количество 1 975

Количество 1 975

github логотип

GHSA-ww72-72c9-q73v

больше 3 лет назад

The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body of an arbitrary node via unknown vectors.

EPSS: Низкий
github логотип

GHSA-wv6v-35vp-99p3

больше 3 лет назад

EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.

EPSS: Низкий
github логотип

GHSA-wv66-4j36-gmp8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name parameter.

EPSS: Низкий
github логотип

GHSA-wrp4-6qx4-xpxp

больше 3 лет назад

The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-wq2m-g52r-49m3

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles.

EPSS: Низкий
github логотип

GHSA-wpgm-86gj-6wrw

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that publish comments.

EPSS: Низкий
github логотип

GHSA-wp8g-2w7h-f8mq

больше 3 лет назад

The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.

EPSS: Низкий
github логотип

GHSA-wp7g-r4mw-j38q

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.

EPSS: Низкий
github логотип

GHSA-wmx8-5mpf-g7gj

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios.

EPSS: Низкий
github логотип

GHSA-wmq2-h8g3-fgwr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.

EPSS: Низкий
github логотип

GHSA-wh5q-mrqr-2xfq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.

EPSS: Низкий
github логотип

GHSA-wfp3-hjq5-f86q

больше 3 лет назад

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-wf53-3973-wc7h

больше 3 лет назад

Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-w9pp-6v27-ph4c

больше 3 лет назад

The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a block that references itself.

EPSS: Низкий
github логотип

GHSA-w8rf-9fp6-x8cj

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of users with administer sharethis permissions via unknown vectors "outside of the Form API."

EPSS: Низкий
github логотип

GHSA-w488-h6xh-7wj6

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.

EPSS: Низкий
github логотип

GHSA-w3rf-6w7g-wchq

больше 3 лет назад

The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-w33x-x8p6-7v77

больше 3 лет назад

Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-w248-ffj2-4v5q

около 3 лет назад

Fix failure to strip Authorization header on HTTP downgrade

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vxm7-x8xr-qhrj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-ww72-72c9-q73v

The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, does not properly enforce privilege requirements for unspecified pages, which allows remote attackers to read the (1) title or (2) body of an arbitrary node via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wv6v-35vp-99p3

EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wv66-4j36-gmp8

Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wrp4-6qx4-xpxp

The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wq2m-g52r-49m3

Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wpgm-86gj-6wrw

Cross-site request forgery (CSRF) vulnerability in the Comment Moderation module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that publish comments.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wp8g-2w7h-f8mq

The Mandrill module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users to obtain password reset links by reading the logs in the Mandrill dashboard.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wp7g-r4mw-j38q

Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wmx8-5mpf-g7gj

Multiple cross-site scripting (XSS) vulnerabilities in components/select.inc in the Webform module 6.x-3.x before 6.x-3.17 and 7.x-3.x before 7.x-3.17 for Drupal, when the "Select (or other)" module is enabled, allow remote authenticated users with the create webform content permission to inject arbitrary web script or HTML via vectors related to (1) checkboxes or (2) radios.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wmq2-h8g3-fgwr

Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wh5q-mrqr-2xfq

Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wfp3-hjq5-f86q

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) Most forwarded, or (3) Dynamic blocks, which allows remote attackers to obtain node titles via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wf53-3973-wc7h

Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w9pp-6v27-ph4c

The Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to cause a denial of service (infinite loop and time out) via a block that references itself.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-w8rf-9fp6-x8cj

Cross-site request forgery (CSRF) vulnerability in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of users with administer sharethis permissions via unknown vectors "outside of the Form API."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w488-h6xh-7wj6

Cross-site scripting (XSS) vulnerability in the aberdeen_breadcrumb function in template.php in the Aberdeen theme 6.x-1.x before 6.x-1.11 for Drupal, when set to append the content title to the breadcrumb, allows remote attackers to inject arbitrary web script or HTML via the content title in a breadcrumb.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-w3rf-6w7g-wchq

The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w33x-x8p6-7v77

Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w248-ffj2-4v5q

Fix failure to strip Authorization header on HTTP downgrade

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-vxm7-x8xr-qhrj

Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу