CVE-2015-6659
- EPSS 14.46%
- Veröffentlicht 24.08.2015 14:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the SQL comment filtering system in the Database API in Drupal 7.x before 7.39 allows remote attackers to execute arbitrary SQL commands via an SQL comment.
CVE-2015-6658
- EPSS 0.76%
- Veröffentlicht 24.08.2015 14:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Autocomplete system in Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to uploading files.
CVE-2015-3234
- EPSS 0.5%
- Veröffentlicht 22.06.2015 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange provide...
CVE-2015-3233
- EPSS 4.94%
- Veröffentlicht 22.06.2015 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- EPSS 0.45%
- Veröffentlicht 22.06.2015 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
CVE-2015-3232
- EPSS 0.44%
- Veröffentlicht 22.06.2015 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.
CVE-2015-2559
- EPSS 0.45%
- Veröffentlicht 25.03.2015 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.
CVE-2010-5312
- EPSS 4.43%
- Veröffentlicht 24.11.2014 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
- EPSS 79.79%
- Veröffentlicht 24.11.2014 15:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
CVE-2014-9015
- EPSS 1.91%
- Veröffentlicht 24.11.2014 15:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.