Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 029

Количество 2 029

github логотип

GHSA-qwh8-647p-vcqr

больше 4 лет назад

Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-qw79-gqrq-4c9p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-qw6j-h2x2-j7fj

около 4 лет назад

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

EPSS: Низкий
github логотип

GHSA-qv94-m7xg-c7qj

около 4 лет назад

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

EPSS: Низкий
github логотип

GHSA-qrg9-7x38-vcrm

около 4 лет назад

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.

EPSS: Низкий
github логотип

GHSA-qr4g-fwv9-54fx

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allow remote attackers to hijack the authentication of administrators for requests that (1) delete the editing protection of a user or (2) delete a certain type of administrative-bypass rule.

EPSS: Низкий
github логотип

GHSA-qqwh-5mr3-9jrg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a submission.

EPSS: Низкий
github логотип

GHSA-qpr6-g969-fw4w

около 4 лет назад

The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks."

EPSS: Низкий
github логотип

GHSA-qp8q-gwf5-hqh2

больше 4 лет назад

Drupal Cross-Site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qmc3-2gf7-hwhf

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart.

EPSS: Низкий
github логотип

GHSA-qm2x-gh76-6m45

больше 4 лет назад

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node.

EPSS: Низкий
github логотип

GHSA-qm25-w56j-5qh8

около 4 лет назад

Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-qjrp-m589-p428

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the node title.

EPSS: Низкий
github логотип

GHSA-qjcf-x39h-78p8

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the admin view in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a crafted field name.

EPSS: Низкий
github логотип

GHSA-qj7w-xc4g-7r9h

около 4 лет назад

The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing.

EPSS: Низкий
github логотип

GHSA-qhg6-w2fh-6xfg

больше 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-qg6j-cgpv-37w6

около 4 лет назад

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

EPSS: Низкий
github логотип

GHSA-qfg8-pvvh-7q2r

около 4 лет назад

The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.

EPSS: Низкий
github логотип

GHSA-qfc2-5h6v-29hp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map.

EPSS: Низкий
github логотип

GHSA-qf4p-9xmf-4whj

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a submission.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qwh8-647p-vcqr

Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qw79-gqrq-4c9p

Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qw6j-h2x2-j7fj

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

2%
Низкий
около 4 лет назад
github логотип
GHSA-qv94-m7xg-c7qj

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qrg9-7x38-vcrm

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qr4g-fwv9-54fx

Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allow remote attackers to hijack the authentication of administrators for requests that (1) delete the editing protection of a user or (2) delete a certain type of administrative-bypass rule.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qqwh-5mr3-9jrg

Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a submission.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qpr6-g969-fw4w

The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks."

1%
Низкий
около 4 лет назад
github логотип
GHSA-qp8q-gwf5-hqh2

Drupal Cross-Site Scripting vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-qmc3-2gf7-hwhf

Cross-site request forgery (CSRF) vulnerability in the Commerce Reorder module before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that add items to the shopping cart.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qm2x-gh76-6m45

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user reference as a reference to the anonymous user, which might allow remote attackers to bypass intended access restrictions to read or modify a node.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qm25-w56j-5qh8

Open redirect vulnerability in the Redirecting click bouncer module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-qjrp-m589-p428

Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the node title.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qjcf-x39h-78p8

Cross-site scripting (XSS) vulnerability in the admin view in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a crafted field name.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qj7w-xc4g-7r9h

The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qhg6-w2fh-6xfg

Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qg6j-cgpv-37w6

The Mime Mail module 6.x-1.x before 6.x-1.1 for Drupal does not properly restrict access to files outside Drupal's publish files directory, which allows remote authenticated users to send arbitrary files as attachments.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qfg8-pvvh-7q2r

The Monster Menus module 7.x-1.x before 7.x-1.15 allows remote attackers to read arbitrary node comments via a crafted URL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-qfc2-5h6v-29hp

Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-qf4p-9xmf-4whj

Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a submission.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу