文件
websafe-kb/07-framework-security/cms/drupal/INDEX.md

11 KiB

Drupal

LAB ONLY | AUTHORIZED TARGETS ONLY | 自动生成索引

  • 系统 ID: drupal
  • 分类: cms
  • 覆盖策略: history-full
  • 总案例数: 70
  • 近 30 天新增/更新: 0
  • 重点 Markdown 案例数: 0
  • 已实证(真实版本): 0
  • 已实证(synthetic): 0
  • 阻塞数: 0
  • 待人工/缺浏览器证据: 70
  • 最近渲染时间: 2026-04-01T09:21:04+00:00

目标约束

  • 适用目标类型: lab-local, lab-public, authorized-third-party
  • 是否允许公网验证: yes, but ownership or authorization is required
  • 授权前提: 资产归属可证明,或已取得书面/明确授权。
  • 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
  • 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作

来源

案例列表

标题 严重度 案例状态 实证状态 实证方式 来源置信度 更新时间 案例页
Drupal core - Critical - Cache poisoning - SA-CORE-2023-006 unknown triage triage-manual synthetic official Wed, 20 Sep 2023 16:23:05 +0000 -
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-008 unknown triage triage-manual synthetic official Wed, 20 Nov 2024 17:29:59 +0000 -
Drupal core - Moderately critical - Gadget chain - SA-CORE-2024-007 unknown triage triage-manual synthetic official Wed, 20 Nov 2024 17:27:28 +0000 -
Drupal core - Less critical - Gadget chain - SA-CORE-2024-006 unknown triage triage-manual synthetic official Wed, 20 Nov 2024 17:25:47 +0000 -
Drupal core - Critical - Cross Site Scripting - SA-CORE-2024-005 unknown triage triage-manual synthetic official Wed, 20 Nov 2024 17:24:02 +0000 -
Drupal core - Moderately critical - Access bypass - SA-CORE-2024-004 unknown triage triage-manual synthetic official Wed, 20 Nov 2024 17:21:58 +0000 -
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003 unknown triage triage-manual synthetic official Wed, 20 Nov 2024 17:20:16 +0000 -
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004 unknown triage triage-manual synthetic official Wed, 19 Mar 2025 18:54:35 +0000 -
Drupal core - Moderately critical - Gadget Chain - SA-CORE-2025-003 unknown triage triage-manual synthetic official Wed, 19 Feb 2025 17:03:28 +0000 -
Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002 unknown triage triage-manual synthetic official Wed, 19 Feb 2025 16:58:10 +0000 -
Drupal core - Critical - Cross site scripting - SA-CORE-2025-001 unknown triage triage-manual synthetic official Wed, 19 Feb 2025 16:49:28 +0000 -
Drupal core - Moderately critical - Access bypass - SA-CORE-2023-005 unknown triage triage-manual synthetic official Wed, 19 Apr 2023 17:06:18 +0000 -
Drupal core - Moderately critical - Denial of Service - SA-CORE-2024-001 unknown triage triage-manual synthetic official Wed, 17 Jan 2024 17:04:39 +0000 -
Drupal core - Moderately critical - Improper error handling - SA-CORE-2024-002 unknown triage triage-manual synthetic official Wed, 16 Oct 2024 16:27:27 +0000 -
Drupal core - Moderately critical - Access bypass - SA-CORE-2023-004 unknown triage triage-manual synthetic official Wed, 15 Mar 2023 16:26:24 +0000 -
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-003 unknown triage triage-manual synthetic official Wed, 15 Mar 2023 16:24:29 +0000 -
Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008 unknown triage triage-manual synthetic official Wed, 12 Nov 2025 20:16:22 +0000 -
Drupal core - Moderately critical - Defacement - SA-CORE-2025-007 unknown triage triage-manual synthetic official Wed, 12 Nov 2025 20:16:21 +0000 -
Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006 unknown triage triage-manual synthetic official Wed, 12 Nov 2025 18:34:02 +0000 -
Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005 unknown triage triage-manual synthetic official Wed, 12 Nov 2025 18:33:05 +0000 -
CVE-2007-0505 high triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2007-0506 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2007-0136 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2007-0124 low triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6646 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6647 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6528 high triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6529 high triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6530 high triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6531 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-6386 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-5608 high triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-5475 medium triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-5476 high triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-5477 low triage triage-manual synthetic official 2025-04-09T00:30:58.490 -
CVE-2006-4947 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4949 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4821 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4717 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4646 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4355 low triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4356 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4360 low triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4120 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4107 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4108 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4109 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-4002 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-3570 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-3473 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-2831 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-2832 low triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-2833 low triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-2742 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-2743 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-2260 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-1225 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-1226 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-1227 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-1228 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2006-0070 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-3973 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-3974 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-3975 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-2498 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-1921 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-2106 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-1871 high triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2005-0682 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -
CVE-2002-1806 medium triage triage-manual synthetic official 2025-04-03T01:03:51.193 -