Risk | High |
Patch available | YES |
Number of vulnerabilities | 5 |
CVE-ID | N/A |
CWE-ID | CWE-264 CWE-601 CWE-78 CWE-94 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
Drupal Web applications / CMS |
Vendor | Drupal |
This security bulletin contains information about 5 vulnerabilities.
EUVDB-ID: #VU15402
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionInstall update from vendor's website.
Drupal: 8.6.0 - 8.6.1, 8.5.0 - 8.5.7
http://www.drupal.org/sa-core-2018-006
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU15403
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Exploit availability: No
DescriptionInstall updates from vendor's website.
Drupal: 8.6.0 - 8.6.1, 8.5.0 - 8.5.7, 7.0 - 7.60
http://www.drupal.org/sa-core-2018-006
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU15404
Risk: Low
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-601 - URL Redirection to Untrusted Site ('Open Redirect')
Exploit availability: No
DescriptionInstall updates from vendor's website.
Drupal: 8.6.0 - 8.6.1, 8.5.0 - 8.5.7
http://www.drupal.org/sa-core-2018-006
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU15405
Risk: High
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Exploit availability: No
DescriptionInstall updates from vendor's website.
Drupal: 8.6.0 - 8.6.1, 8.5.0 - 8.5.7, 7.0 - 7.60
http://www.drupal.org/sa-core-2018-006
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU15406
Risk: Medium
CVSSv3.1:
CVE-ID: N/A
CWE-ID:
CWE-94 - Improper Control of Generation of Code ('Code Injection')
Exploit availability: No
DescriptionInstall updates from vendor's website.
Drupal: 8.6.0 - 8.6.1, 8.5.0 - 8.5.7
http://www.drupal.org/sa-core-2018-006
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?