Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sumit Datta

#21889of 53,635
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2009-4800
6.5
2009-07-08
Drupal · Drupal · CVE-2009-2372
**Name of the Vulnerable Software and Affected Versions** Drupal versions 6.x before 6.13 **Description** The issue allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature, because it does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format. **Recommendations** For versions 6.x before 6.13, update to version 6.13 or later to resolve the issue.
PT-2009-4802
4.3
2009-07-08
Drupal · Drupal · CVE-2009-2374
**Name of the Vulnerable Software and Affected Versions** Drupal versions 5.x before 5.19 Drupal versions 6.x before 6.13 **Description** The issue arises from improper sanitization of failed login attempts for pages containing sortable tables. This can lead to the exposure of usernames and passwords through two main vectors: (1) the HTTP referer header of external web sites that are visited from those links, (2) when page caching is enabled, the Drupal page cache. **Recommendations** For Drupal versions 5.x before 5.19, update to version 5.19 or later to resolve the issue. For Drupal versions 6.x before 6.13, update to version 6.13 or later to resolve the issue.