PT-2009-4064 · Drupal · Drupal

Moritz Naumann

·

Published

2009-05-06

·

Updated

2009-05-20

·

CVE-2009-1576

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Drupal versions 5.x prior to 5.17 Drupal versions 6.x prior to 6.11
Description: The issue allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the site's front page with a crafted URL, causing form data to be sent to an attacker-controlled site. This might be related to multiple / (slash) characters not being properly handled by includes/bootstrap.inc, as demonstrated using the search box. It can be leveraged to conduct cross-site request forgery (CSRF) attacks.
Recommendations: For Drupal versions 5.x prior to 5.17, update to version 5.17 or later. For Drupal versions 6.x prior to 6.11, update to version 6.11 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-1576
DSA-1792-1

Affected Products

Drupal