PT-2009-4064 · Drupal · Drupal

Moritz Naumann

·

Publicado

2009-05-06

·

Atualizado

2009-05-20

·

CVE-2009-1576

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Drupal versions 5.x prior to 5.17 Drupal versions 6.x prior to 6.11
Description: The issue allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the site's front page with a crafted URL, causing form data to be sent to an attacker-controlled site. This might be related to multiple / (slash) characters not being properly handled by includes/bootstrap.inc, as demonstrated using the search box. It can be leveraged to conduct cross-site request forgery (CSRF) attacks.
Recommendations: For Drupal versions 5.x prior to 5.17, update to version 5.17 or later. For Drupal versions 6.x prior to 6.11, update to version 6.11 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-1576
DSA-1792-1

Produtos afetados

Drupal