Drupal是一个开源的内容管理系统(CMS)平台。 Drupal用户保护模块5.x-1.4之前的5.x版本和6.x-1.3之前的6.x版本中存在多个跨站请求伪造漏洞。远程攻击者可以通过劫持管理员的身份认证来发送(1)删除用户的编辑保护或(2)删除特定的管理绕过规则种类的请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-3555 | Apache HTTP Server 信任管理问题漏洞 | |
| CVE-2009-3921 | Drupal Smartqueue OG模块安全许可和信息泄露漏洞 | |
| CVE-2009-3920 | Drupal NGP COO/CWP Integration模块访问控制和信息泄露漏洞 | |
| CVE-2009-3919 | Drupal NGP COO/CWP Integration模块安全绕过和HTML注入漏洞 | |
| CVE-2009-3918 | Drupal Zoomify模块HTML注入漏洞 | |
| CVE-2009-3917 | Drupal S5 Presentation Player模块HTML注入漏洞 | |
| CVE-2009-3916 | Drupal Node Hierarchy模块跨站脚本漏洞 | |
| CVE-2009-3915 | Drupal Link模块跨站脚本攻击漏洞 | |
| CVE-2009-3914 | Drupal Temporary Invitation模块跨站脚本漏洞 | |
| CVE-2009-3913 | Xerox Fiery WebTools 'summary.php' SQL注入漏洞 | |
| CVE-2009-3912 | TFTgallery 'index.php' 目录遍历漏洞 | |
| CVE-2009-3911 | TFTgallery 'settings.php' 跨站脚本攻击漏洞 | |
| CVE-2009-3726 | Linux kernel 资源管理错误漏洞 | |
| CVE-2009-3886 | Sun Java SE "Java Web Start"应用未明安全漏洞 | |
| CVE-2009-3885 | Sun Java SE "BMP"方法 拒绝服务攻击漏洞 | |
| CVE-2009-3884 | Sun Java SE和OpenJDK 方法"TimeZone.getTimeZone" 信息泄露漏洞 | |
| CVE-2009-3883 | Sun Java SE和OpenJDK 特征"PL&F" 多个未明安全漏洞 | |
| CVE-2009-3882 | Sun Java SE和OpenJDK 应用"Swing" 多个未明安全漏洞 | |
| CVE-2009-3881 | Sun Java SE和OpenJDK "ClassLoader" 权限获得和信息泄露漏洞 | |
| CVE-2009-3880 | Sun Java SE和OpenJDK "Abstract Window Toolkit (AWT)" 访问控制和信息泄露漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet