CVE-2010-2250
- EPSS 0.73%
- Veröffentlicht 07.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 01:16:14
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
CVE-2010-2471
- EPSS 0.55%
- Veröffentlicht 06.11.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 01:16:44
Drupal versions 5.x and 6.x has open redirection
CVE-2019-11876
- EPSS 0.21%
- Veröffentlicht 24.05.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:56
In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by Reflected XSS. Exploitation by a malicious actor requires the user to follow the initial stages of the setup (accepting terms and ...
CVE-2019-10909
- EPSS 0.38%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:06
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
CVE-2019-10910
- EPSS 12.5%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:07
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-inject...
CVE-2019-10911
- EPSS 0.29%
- Veröffentlicht 16.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:07
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functional...
CVE-2019-11831
- EPSS 9.52%
- Veröffentlicht 09.05.2019 04:29:01
- Zuletzt bearbeitet 21.11.2024 04:21:50
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/b...
CVE-2019-11358
- EPSS 0.94%
- Veröffentlicht 20.04.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:56
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the n...
CVE-2019-6341
- EPSS 54.56%
- Veröffentlicht 26.03.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:26
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) ...
CVE-2019-6340
- EPSS 94.44%
- Veröffentlicht 21.02.2019 21:29:00
- Zuletzt bearbeitet 07.11.2025 19:36:49
Some field types do not properly sanitize data from non-form sources in Drupal 8.5.x before 8.5.11 and Drupal 8.6.x before 8.6.10. This can lead to arbitrary PHP code execution in some cases. A site is only affected by this if one of the following co...