Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-6169

Опубликовано: 19 фев. 2009
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:drupal:localization_client:*:*:*:*:*:*:*:*
Версия до 5.x-1.0 (включая)
cpe:2.3:a:drupal:localization_client:*:*:*:*:*:*:*:*
Версия до 6.x-1.5 (включая)
cpe:2.3:a:drupal:localization_client:5.x-1.xdev:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_client:6.x-1.0:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_client:6.x-1.1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_client:6.x-1.2:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_client:6.x-1.3:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_client:6.x-1.4:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_client:6.x-1.xdev:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_server:*:*:*:*:*:*:*:*
Версия до 5.x-1.0alpha4 (включая)
cpe:2.3:a:drupal:localization_server:*:*:*:*:*:*:*:*
Версия до 6.x-1.0alpha1 (включая)
cpe:2.3:a:drupal:localization_server:5.x-1.0alpha1:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_server:5.x-1.0alpha2:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_server:5.x-1.0alpha3:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_server:5.x-1.xdev:*:*:*:*:*:*:*
cpe:2.3:a:drupal:localization_server:6.x-1.xdev:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00205
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

github
больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."

EPSS

Процентиль: 43%
0.00205
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-352