PT-2009-4064 · Drupal · Drupal
Moritz Naumann
·
Publicado
2009-05-06
·
Atualizado
2009-05-20
·
CVE-2009-1576
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Drupal versions 5.x prior to 5.17
Drupal versions 6.x prior to 6.11
Description:
The issue allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the site's front page with a crafted URL, causing form data to be sent to an attacker-controlled site. This might be related to multiple / (slash) characters not being properly handled by includes/bootstrap.inc, as demonstrated using the search box. It can be leveraged to conduct cross-site request forgery (CSRF) attacks.
Recommendations:
For Drupal versions 5.x prior to 5.17, update to version 5.17 or later.
For Drupal versions 6.x prior to 6.11, update to version 6.11 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal