PT-2006-6191 · Drupal · Drupal

Garvin Hicking

·

Published

2006-10-24

·

Updated

2018-10-17

·

CVE-2006-5476

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Drupal versions 4.6.x through 4.6.9 Drupal versions 4.7.x through 4.7.3
Description A cross-site request forgery issue allows remote attackers to perform unauthorized actions as an arbitrary user via unspecified vectors.
Recommendations For versions 4.6.x through 4.6.9, update to version 4.6.10 or later. For versions 4.7.x through 4.7.3, update to version 4.7.4 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5476

Affected Products

Drupal