The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
We have discovered 134,617 live websites that are affected by CVE-2016-9450.
Product | |
Category | Content Management System |
Vulnerable Domains | 134,617 live websites (53.59% of Drupal install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 34 versions ( 11.15% of all versions) |
![]() | 42,214 websites |
![]() | 13,945 websites |
![]() | 11,934 websites |
![]() | 10,390 websites |
![]() | 4,250 websites |
![]() | 3,941 websites |
![]() | 3,691 websites |
![]() | 3,387 websites |
![]() | 2,840 websites |
![]() | 2,503 websites |
.com | 37,037 websites |
.org | 11,561 websites |
.ru | 9,893 websites |
.de | 7,228 websites |
.fr | 4,924 websites |
.be | 4,361 websites |
.edu | 4,035 websites |
.net | 3,307 websites |
.it | 2,936 websites |
.nl | 2,763 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
******.org | ![]() | *** | |
***.org | ![]() | *,*** | |
********.gov | ![]() | *,*** | |
******.gov | ![]() | *,*** | |
***.**.gov | ![]() | *,*** | |
******.edu | ![]() | *,*** | |
***.gov | ![]() | *,*** | |
****.org | ![]() | *,*** | |
***.com | ![]() | *,*** | |
*******.com | ![]() | *,*** |
FAQ