Show filters
285 Total Results
Displaying 61-70 of 285
Sort by:
Attacker Value
Unknown

CVE-2020-36193

Disclosure Date: January 18, 2021 (last updated February 22, 2025)
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Attacker Value
Unknown

CVE-2020-35191

Disclosure Date: December 17, 2020 (last updated February 22, 2025)
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Attacker Value
Unknown

CVE-2020-13671

Disclosure Date: November 20, 2020 (last updated February 22, 2025)
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.
Attacker Value
Unknown

CVE-2019-6342

Disclosure Date: May 28, 2020 (last updated November 27, 2024)
An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.
Attacker Value
Unknown

CVE-2020-9281

Disclosure Date: March 07, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Attacker Value
Unknown

CVE-2011-2715

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
Attacker Value
Unknown

CVE-2011-2714

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
Attacker Value
Unknown

CVE-2011-2726

Disclosure Date: November 15, 2019 (last updated November 27, 2024)
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
Attacker Value
Unknown

CVE-2010-2472

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
Attacker Value
Unknown

CVE-2010-2473

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.