PT-2013-6023 · Drupal · Drupal
Publicado
2013-11-30
·
Atualizado
2014-01-14
·
CVE-2013-6385
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Drupal versions 6.x before 6.29
Drupal versions 7.x before 7.24
Description
The issue affects the form API in Drupal, potentially allowing remote attackers to trigger application-specific impacts, such as arbitrary code execution, via application-specific vectors when used with unspecified third-party modules. This occurs because the form API performs form validation even when CSRF validation has failed.
Recommendations
For Drupal 6.x, update to version 6.29 or later.
For Drupal 7.x, update to version 7.24 or later.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal