PT-2013-6023 · Drupal · Drupal

Publicado

2013-11-30

·

Atualizado

2014-01-14

·

CVE-2013-6385

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 6.x before 6.29 Drupal versions 7.x before 7.24
Description The issue affects the form API in Drupal, potentially allowing remote attackers to trigger application-specific impacts, such as arbitrary code execution, via application-specific vectors when used with unspecified third-party modules. This occurs because the form API performs form validation even when CSRF validation has failed.
Recommendations For Drupal 6.x, update to version 6.29 or later. For Drupal 7.x, update to version 7.24 or later.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6385
DSA-2804-1
DSA-2828-1
MGASA-2013-0359

Produtos afetados

Drupal