Show filters
488 Total Results
Displaying 161-170 of 488
Sort by:
Attacker Value
Unknown

CVE-2017-6928

Disclosure Date: March 01, 2018 (last updated November 26, 2024)
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which one module is trying to grant access to the file and another is trying to deny it, leading to an access bypass vulnerability. This vulnerability is mitigated by the fact that it only occurs for unusual site configurations.
0
Attacker Value
Unknown

CVE-2015-7943

Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
0
Attacker Value
Unknown

CVE-2015-7880

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.
0
Attacker Value
Unknown

CVE-2015-2750

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
0
Attacker Value
Unknown

CVE-2015-2749

Disclosure Date: September 13, 2017 (last updated November 26, 2024)
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
0
Attacker Value
Unknown

CVE-2017-6919

Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.
0
Attacker Value
Unknown

CVE-2017-6377

Disclosure Date: March 16, 2017 (last updated November 26, 2024)
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
0
Attacker Value
Unknown

CVE-2017-6379

Disclosure Date: March 16, 2017 (last updated November 26, 2024)
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.
0
Attacker Value
Unknown

CVE-2017-6381

Disclosure Date: March 16, 2017 (last updated November 26, 2024)
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies aren't normal installed. You might be vulnerable to this if you are running a version of Drupal before 8.2.2. To be sure you aren't vulnerable, you can remove the <siteroot>/vendor/phpunit directory from your production deployments
0
Attacker Value
Unknown

CVE-2016-9451

Disclosure Date: November 25, 2016 (last updated November 25, 2024)
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
0