Drupal

Drupal

284 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.71%
  • Veröffentlicht 28.03.2012 10:54:59
  • Zuletzt bearbeitet 16.06.2026 22:48:42

Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of...

Exploit
  • EPSS 1.64%
  • Veröffentlicht 23.09.2011 23:55:03
  • Zuletzt bearbeitet 16.06.2026 23:33:49

Drupal 7.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/simpletest/tests/upgrade/drupal-6.upload.database.php and cert...

  • EPSS 3.06%
  • Veröffentlicht 27.07.2011 02:55:02
  • Zuletzt bearbeitet 16.06.2026 23:31:47

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table.

  • EPSS 2.37%
  • Veröffentlicht 29.09.2010 17:00:05
  • Zuletzt bearbeitet 16.06.2026 23:23:19

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by le...

  • EPSS 2.37%
  • Veröffentlicht 29.09.2010 17:00:05
  • Zuletzt bearbeitet 16.06.2026 23:23:20

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an asserti...

  • EPSS 2.37%
  • Veröffentlicht 29.09.2010 17:00:04
  • Zuletzt bearbeitet 16.06.2026 23:22:06

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an as...

  • EPSS 1.56%
  • Veröffentlicht 21.09.2010 20:00:02
  • Zuletzt bearbeitet 16.06.2026 23:22:06

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to bypass the intended restrictions on downloading a fil...

  • EPSS 1.4%
  • Veröffentlicht 21.09.2010 20:00:02
  • Zuletzt bearbeitet 16.06.2026 23:22:06

The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a crafted URL, related to an "unpublishing bypass" is...

  • EPSS 1.37%
  • Veröffentlicht 21.09.2010 20:00:02
  • Zuletzt bearbeitet 16.06.2026 23:22:06

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a t...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 21.12.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:13:32

Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide conta...